Compare commits

...

317 Commits

Author SHA1 Message Date
yunion-ci-robot
1296f7292e Merge pull request #8223 from yousong/automated-cherry-pick-of-#8222-upstream-release-3.0
Automated cherry pick of #8222: webconsole: ssh: each argument on its own line
2020-10-10 15:40:17 +08:00
Yousong Zhou
44b560adba webconsole: ssh: add keyboard-interactive as an option
For ESXi 6.0

  Authentications that can continue: publickey,keyboard-interactive
2020-10-10 14:48:59 +08:00
Yousong Zhou
7b2c63b60b webconsole: ssh: each argument on its own line 2020-10-10 14:48:59 +08:00
Zexi Li
af6d97823a Merge pull request #7875 from rainzm/automated-cherry-pick-of-#7870-upstream-release-3.0
Automated cherry pick of #7870: fix(esxiagent): add HostDelayTaskWorkerCount
2020-09-11 20:56:21 +08:00
Zexi Li
e67837c5b8 Merge pull request #7867 from wanyaoqi/automated-cherry-pick-of-#7836-upstream-release-3.0
Automated cherry pick of #7836: host: fix rbd storage cache iso image
2020-09-11 20:54:40 +08:00
rainzm
99381ac86f fix(esxiagent): add HostDelayTaskWorkerCount
之前,HostDelayWorker 是通过 hostutils.InitWorkerManager 来初始化,
worker的数量依赖于options.HostOptions.DefaultRequestWorkerCount, 因为
这个options没有经过初始化,所以就是0,导致worker count的数量变为1。

现在增加了 HostDelayTaskWorkerCount 来管理这个count,默认值为8。
2020-09-11 17:24:18 +08:00
wanyaoqi
73be2088d1 host: fix rbd storage cache iso image 2020-09-10 23:30:05 +08:00
wanyaoqi
1aef4c5435 fix get storage capacity on init' (#7691) 2020-09-01 00:59:36 +08:00
Zexi Li
23cc8eff96 Merge pull request #7627 from wanyaoqi/automated-cherry-pick-of-#7623-upstream-release-3.0
Automated cherry pick of #7623: fix gpfs check mountpoint
2020-08-25 17:41:32 +08:00
wanyaoqi
718cd4527a fix gpfs check mountpoint 2020-08-25 15:54:06 +08:00
Zexi Li
1e0cfa9509 Merge pull request #7539 from wanyaoqi/automated-cherry-pick-of-#7530-upstream-release-3.0
Automated cherry pick of #7530: fix mount xfs
2020-08-11 11:16:48 +08:00
wanyaoqi
014feeb399 fix mount xfs 2020-08-10 20:07:11 +08:00
Zexi Li
e7f2dc5d86 Merge pull request #7451 from tb365/automated-cherry-pick-of-#7447-upstream-release-3.0
Automated cherry pick of #7447: aws elb listener&rule name too long fix
2020-08-02 10:09:01 +08:00
wanyaoqi
3e22345216 fix cache non lvm disks (#7463) 2020-08-01 21:12:03 +08:00
tangbin
4ed140e796 aws elb listener&rule name too long fix 2020-08-01 11:13:42 +08:00
Zexi Li
a793e617bb Merge pull request #7445 from wanyaoqi/automated-cherry-pick-of-#7441-upstream-release-3.0
Automated cherry pick of #7441: fix deploy admin auth key
2020-08-01 00:08:34 +08:00
wanyaoqi
6f41845086 fix deploy admin auth key 2020-07-31 23:27:57 +08:00
Zexi Li
d2c10534cf baremetal: fix hpssactl split last LV size out of limit (#7430) 2020-07-31 22:37:02 +08:00
Zexi Li
e1e3f69e45 Merge pull request #7423 from ioito/automated-cherry-pick-of-#7417-upstream-release-3.0
Automated cherry pick of #7417: fix: avoid lost backend params
2020-07-31 18:08:14 +08:00
Zexi Li
c6a7064f24 Merge pull request #7411 from ioito/automated-cherry-pick-of-#7405-upstream-release-3.0
Automated cherry pick of #7405: fix: avoid account sync deadlock
2020-07-31 18:05:40 +08:00
Qu Xuan
07efbb4e16 fix: avoid lost backend params 2020-07-31 17:20:48 +08:00
Qu Xuan
89147a4243 fix: avoid account sync deadlock 2020-07-31 16:41:24 +08:00
Zexi Li
eaaf2d976a Merge pull request #7363 from ioito/automated-cherry-pick-of-#7359-upstream-release-3.0
Automated cherry pick of #7359: fix: 修复vm绑定重复安全组
2020-07-28 20:56:14 +08:00
Qu Xuan
bf3c3befec fix: 修复vm绑定重复安全组 2020-07-28 18:17:42 +08:00
yunion-ci-robot
85f3f0ac56 Merge pull request #7307 from wanyaoqi/automated-cherry-pick-of-#7302-upstream-release-3.0
Automated cherry pick of #7302: fix clone clean pending usage
2020-07-24 22:50:41 +08:00
wanyaoqi
a0235d6bb5 fix clone clean pending usage 2020-07-23 18:39:40 +08:00
Zexi Li
f8189a0623 Merge pull request #7298 from wanyaoqi/automated-cherry-pick-of-#7294-upstream-release-3.0
Automated cherry pick of #7294: fix snapshot clean pending usage
2020-07-23 13:48:22 +08:00
wanyaoqi
f3ff18ea2f fix snapshot clean pending usage 2020-07-23 11:41:41 +08:00
Zexi Li
86eaefa0db Merge pull request #7290 from tb365/automated-cherry-pick-of-#7286-upstream-release-3.0
Automated cherry pick of #7286: apigateway host imports data validate
2020-07-22 21:44:28 +08:00
tangbin
53f76e2ea7 format fix 2020-07-22 18:12:14 +08:00
tangbin
6b4a8cd866 fix empty else 2020-07-22 18:12:13 +08:00
tangbin
731082303e fix host import 2020-07-22 18:12:13 +08:00
tangbin
ec4e466c50 fix huawei delete resource 2020-07-22 18:12:13 +08:00
tangbin
1a6030beee fix huawei elb disable healthcheck 2020-07-22 18:12:13 +08:00
tangbin
07bef07ac8 lb sync project fix 2020-07-22 18:12:12 +08:00
tangbin
1bbdfc9199 add more log 2020-07-22 18:05:56 +08:00
tangbin
2afeece9ba apigateway host imports data validate 2020-07-22 18:05:56 +08:00
Zexi Li
e737314cb2 Merge pull request #7285 from rainzm/automated-cherry-pick-of-#7281-upstream-release-3.0
Automated cherry pick of #7281: fix(esxi): Select correct unitNumber for ide control when creating disk
2020-07-22 13:52:49 +08:00
Rain Zheng
87f65c5fa7 fix(esxi): Select correct unitNumber for ide control when creating disk 2020-07-21 20:52:32 +08:00
Zexi Li
0d71f5da1c Merge pull request #7260 from tb365/automated-cherry-pick-of-#7237-upstream-release-3.0
Automated cherry pick of #7237: huawei eip delete fix
2020-07-20 20:47:26 +08:00
tangbin
0e606419ee huawei eip delete fix 2020-07-20 10:50:33 +08:00
yunion-ci-robot
c465b511f4 Merge pull request #7208 from zexi/automated-cherry-pick-of-#7201-upstream-release-3.0
Automated cherry pick of #7201: webconsole: fix old session make new session closed
2020-07-16 20:16:20 +08:00
Zexi Li
02298c8450 webconsole: fix old session make new session closed 2020-07-16 18:51:52 +08:00
Zexi Li
07b088e549 Merge pull request #7185 from ioito/automated-cherry-pick-of-#7177-upstream-release-3.0
Automated cherry pick of #7177: fix: 避免华为云安全组规则删除失败
2020-07-16 10:16:45 +08:00
Qu Xuan
7a70c19ce3 fix: 避免华为云安全组规则删除失败 2020-07-15 17:15:14 +08:00
Zexi Li
0d980e51f6 Merge pull request #7129 from wanyaoqi/bugfix/wyq/cherry-pick-7125-3.0
Manual cherry pick of #7125: fix rbd storage set storage info
2020-07-10 20:16:11 +08:00
wanyaoqi
62375a75c9 fix rbd storage set storage info 2020-07-10 15:00:18 +08:00
Zexi Li
7b0dd1e7a3 Merge pull request #7110 from wanyaoqi/automated-cherry-pick-of-#7106-upstream-release-3.0
Automated cherry pick of #7106: fix set storage info bind mount
2020-07-09 21:20:07 +08:00
wanyaoqi
ad095330bf fix set storage info bind mount 2020-07-09 14:57:39 +08:00
Zexi Li
b13e3230d8 Merge pull request #7065 from rainzm/automated-cherry-pick-of-#7061-upstream-release-3.0
Automated cherry pick of #7061: Update docker image onecloud-base and its references
2020-07-07 11:13:00 +08:00
rainzm
ca8709ee08 Update docker image onecloud-base and its references 2020-07-06 21:08:25 +08:00
Zexi Li
617ee1c461 Merge pull request #7040 from swordqiu/automated-cherry-pick-of-#7036-upstream-release-3.0
Automated cherry pick of #7036: fix: cloud account sync may block
2020-07-04 12:09:37 +08:00
Qiu Jian
3e4b0894a7 fix: cloud account sync may block 2020-07-04 10:26:16 +08:00
Zexi Li
370037f561 Merge pull request #7016 from wanyaoqi/automated-cherry-pick-of-#7006-upstream-release-3.0
Automated cherry pick of #7006: bind mount nfs storage path
2020-07-02 17:42:35 +08:00
wanyaoqi
8ebf1d44e8 bind mount nfs storage path 2020-07-02 17:38:33 +08:00
Zexi Li
a8a7edda6e Merge pull request #6979 from wanyaoqi/automated-cherry-pick-of-#6975-upstream-release-3.0
Automated cherry pick of #6975: fix deploy backup server order
2020-06-30 23:08:55 +08:00
wanyaoqi
880686d690 fix deploy backup server order 2020-06-30 22:11:04 +08:00
Zexi Li
aea5736f14 Merge pull request #6940 from swordqiu/automated-cherry-pick-of-#6936-upstream-release-3.0
Automated cherry pick of #6936: fix: sort quota list result by usage rate
2020-06-23 23:28:18 +08:00
Qiu Jian
0feebf0b69 fix: sort quota list result by usage rate 2020-06-23 22:28:00 +08:00
Zexi Li
5fed98ec31 Merge pull request #6925 from swordqiu/automated-cherry-pick-of-#6921-upstream-release-3.0
Automated cherry pick of #6921: fix: simplify forbidden user login message
2020-06-23 21:26:11 +08:00
Qiu Jian
3276f8e387 fix: simplify forbidden user login message 2020-06-23 17:48:50 +08:00
yunion-ci-robot
7a9c8de48f Merge pull request #6910 from wanyaoqi/automated-cherry-pick-of-#6906-upstream-release-3.0
Automated cherry pick of #6906: disable dhclient
2020-06-22 23:38:00 +08:00
wanyaoqi
40f23eeef3 disable dhclient 2020-06-22 21:32:02 +08:00
Zexi Li
a953c56e50 Merge pull request #6897 from yousong/automated-cherry-pick-of-#6893-upstream-release-3.0
Automated cherry pick of #6893: cloudcommon: app: cosmetic change
2020-06-22 09:17:39 +08:00
Yousong Zhou
afbc7a9096 cloudcommon: policy: fix interval and oneshot sync
Reduce CPU utilization caused by queued time.AfterFunc calls
2020-06-21 18:34:41 +08:00
Yousong Zhou
32995e2acf cloudcommon: app: cosmetic change 2020-06-21 18:34:41 +08:00
yunion-ci-robot
10b767b6c6 Merge pull request #6888 from swordqiu/automated-cherry-pick-of-#6885-upstream-release-3.0
Automated cherry pick of #6885: fix: wrong cloud provider status when sync disconnected cloud account
2020-06-19 09:49:08 +08:00
Qiu Jian
b0c58216b2 fix: wrong cloud provider status when sync disconnected cloud account 2020-06-19 01:23:49 +08:00
yunion-ci-robot
776551f9e6 Merge pull request #6867 from yousong/automated-cherry-pick-of-#6859-upstream-release-3.0
Automated cherry pick of #6859: cloudaccounts: one sync task in queue per cloudaccount
2020-06-18 23:17:04 +08:00
Zexi Li
efd481bc83 Merge pull request #6874 from ioito/automated-cherry-pick-of-#6871-upstream-release-3.0
Automated cherry pick of #6871: fix: 避免同步删除失败
2020-06-18 19:06:01 +08:00
Qu Xuan
6815918e04 fix: 避免同步删除失败 2020-06-18 17:23:13 +08:00
Yousong Zhou
9b94f70804 cloudaccounts: one sync task in queue per cloudaccount 2020-06-18 17:12:58 +08:00
Zexi Li
cdf41a6c81 Merge pull request #6843 from zexi/automated-cherry-pick-of-#6840-upstream-release-3.0
Automated cherry pick of #6840: scheduler: fix memory over committed
2020-06-17 18:49:45 +08:00
Zexi Li
eaada436b9 Merge pull request #6857 from yousong/automated-cherry-pick-of-#6837-upstream-release-3.0
Automated cherry pick of #6837: appsrv: ring: release ring content on pop
2020-06-17 11:24:44 +08:00
Yousong Zhou
ec0264f807 appsrv: rework TestRing 2020-06-17 10:54:15 +08:00
Yousong Zhou
6faaf905a0 appsrv: ring: release ring content on pop 2020-06-17 10:54:15 +08:00
Zexi Li
4138871ceb Merge pull request #6852 from swordqiu/automated-cherry-pick-of-#6849-upstream-release-3.0
Automated cherry pick of #6849: fix: disable policy rule compaction
2020-06-17 10:29:14 +08:00
Qiu Jian
3b9cd6da73 fix: policy allow if one of the matching rules is allow 2020-06-16 23:12:07 +08:00
Qiu Jian
9be75f2368 fix: disable policy rule compaction 2020-06-16 23:12:07 +08:00
Zexi Li
78b70d950d Merge pull request #6847 from wanyaoqi/automated-cherry-pick-of-#6844-upstream-release-3.0
Automated cherry pick of #6844: fix cpu usage metrics
2020-06-16 21:00:55 +08:00
wanyaoqi
99f058aad0 fix cpu usage metrics 2020-06-16 20:45:40 +08:00
Zexi Li
9451b707ae Merge pull request #6827 from wanyaoqi/automated-cherry-pick-of-#6824-upstream-release-3.0
Automated cherry pick of #6824: fix windows install regedit record
2020-06-16 20:12:40 +08:00
Zexi Li
03565249a3 scheduler: fix memory over committed 2020-06-16 19:19:13 +08:00
wanyaoqi
7f7ea28684 fix windows install regedit record 2020-06-15 10:59:21 +08:00
Zexi Li
b62340a032 Merge pull request #6820 from yousong/automated-cherry-pick-of-#6817-upstream-release-3.0
Automated cherry pick of #6817: guestnetworks: use math/rand instead of crypto/rand
2020-06-12 10:09:33 +08:00
Yousong Zhou
a889c585e7 guestnetworks: reduce odds of collision seeded by epoch seconds 2020-06-11 21:23:19 +08:00
Yousong Zhou
5b59e1cc5f guestnetworks: use math/rand instead of crypto/rand 2020-06-11 21:23:18 +08:00
Zexi Li
4f6dac72ff Merge pull request #6814 from ioito/automated-cherry-pick-of-#6810-upstream-release-3.0
Automated cherry pick of #6810: fix: 避免openstack磁盘和存储窜位
2020-06-11 17:52:28 +08:00
Zexi Li
037c3dd4c3 Merge pull request #6806 from zexi/automated-cherry-pick-of-#6803-upstream-release-3.0
Automated cherry pick of #6803: webconsole: fix version and others handler not handle
2020-06-11 17:50:19 +08:00
Qu Xuan
3ac79f8d0a fix: 避免openstack磁盘和存储窜位 2020-06-11 14:15:12 +08:00
Zexi Li
55cde2abc0 Merge pull request #6800 from wanyaoqi/automated-cherry-pick-of-#6797-upstream-release-3.0
Automated cherry pick of #6797: fix host list servers filter
2020-06-10 17:06:09 +08:00
Zexi Li
fbbf738a1c webconsole: fix version and others handler not handle 2020-06-10 17:03:41 +08:00
wanyaoqi
8c670a116d fix host list servers filter 2020-06-10 14:09:09 +08:00
Zexi Li
7a1ce75307 Merge pull request #6789 from rainzm/automated-cherry-pick-of-#6786-upstream-release-3.0
Automated cherry pick of #6786: fix: Hanle the error of vdisk.GetIStorage in syncCloudDisk
2020-06-10 11:28:12 +08:00
Zexi Li
fc825b87c2 Merge pull request #6766 from ioito/automated-cherry-pick-of-#6663-upstream-release-3.0
Automated cherry pick of #6663: fix: 优化安全组同步逻辑
2020-06-10 11:19:08 +08:00
Zexi Li
0265f6eed4 Merge pull request #6785 from rainzm/automated-cherry-pick-of-#6782-upstream-release-3.0
Automated cherry pick of #6782: fix: Add '/version' handler for notify
2020-06-10 10:19:01 +08:00
Zexi Li
a3e8dd22c1 Merge pull request #6794 from swordqiu/automated-cherry-pick-of-#6791-upstream-release-3.0
Automated cherry pick of #6791: fix: policy-explain not working properly
2020-06-10 09:53:09 +08:00
Qiu Jian
422793d4b4 fix: policy-explain not working properly 2020-06-09 22:31:06 +08:00
rainzm
474c78a61a fix: Hanle the error of vdisk.GetIStorage in syncCloudDisk 2020-06-09 19:50:58 +08:00
rainzm
9a58765d18 fix: Add '/version' handler for notify 2020-06-09 18:56:03 +08:00
Qu Xuan
b0f33a8b2c fix: 优化安全组同步逻辑 2020-06-08 16:57:29 +08:00
yunion-ci-robot
5ca6eecc01 Merge pull request #6695 from ioito/automated-cherry-pick-of-#6692-upstream-release-3.0
Automated cherry pick of #6692: fix: 返回object默认acl
2020-06-06 10:59:48 +08:00
Qu Xuan
0c6323bc26 fix: 返回object默认acl 2020-06-05 11:01:18 +08:00
Zexi Li
679385dc82 Merge pull request #6747 from wanyaoqi/automated-cherry-pick-of-#6744-upstream-release-3.0
Automated cherry pick of #6744: bind mount local image path to container path
2020-06-04 21:24:25 +08:00
wanyaoqi
fe819b30b1 bind mount local image path to container path 2020-06-04 20:23:58 +08:00
Zexi Li
b51daa01d5 Merge pull request #6725 from ioito/automated-cherry-pick-of-#6722-upstream-release-3.0
Automated cherry pick of #6722: fix: 添加region翻译
2020-06-04 10:28:36 +08:00
Qu Xuan
a94ef0ac31 fix: 添加region翻译 2020-06-03 20:42:07 +08:00
Zexi Li
920cfef241 Merge pull request #6716 from wanyaoqi/automated-cherry-pick-of-#6713-upstream-release-3.0
Automated cherry pick of #6713: isolated device manager:
2020-06-03 17:25:23 +08:00
wanyaoqi
78e55702ac isolated device manager:
- fix find boot_vga got No such file or dirtory
2020-06-03 15:53:43 +08:00
yunion-ci-robot
ad3c1b01a7 Merge pull request #6689 from ioito/automated-cherry-pick-of-#6686-upstream-release-3.0
Automated cherry pick of #6686: fix: 避免锁超时
2020-06-02 13:59:42 +08:00
Qu Xuan
4588fdabad fix: 避免锁超时 2020-06-02 11:15:43 +08:00
Zexi Li
266f684581 Merge pull request #6678 from ioito/automated-cherry-pick-of-#6675-upstream-release-3.0
Automated cherry pick of #6675: fix: add us-west4 for google region
2020-06-02 10:00:28 +08:00
Zexi Li
5f5097058a Merge pull request #6673 from wanyaoqi/automated-cherry-pick-of-#6670-upstream-release-3.0
Automated cherry pick of #6670: get snapshots order by created at asc
2020-06-02 09:58:46 +08:00
Qu Xuan
51f64a9605 fix: add us-west4 for google region 2020-06-01 18:29:21 +08:00
wanyaoqi
e81d1848c4 get snapshots order by created at asc 2020-06-01 15:10:59 +08:00
Zexi Li
18c4bcd9db Merge pull request #6656 from swordqiu/automated-cherry-pick-of-#6636-upstream-release-3.0
Automated cherry pick of #6636: fix: ignore match weights when searching matched policysets
2020-05-29 14:20:40 +08:00
Zexi Li
807d5ca119 Merge pull request #6653 from wanyaoqi/automated-cherry-pick-of-#6650-upstream-release-3.0
Automated cherry pick of #6650: fix migrate with multi local storage
2020-05-29 14:19:06 +08:00
Qiu Jian
df9c9431a6 fix: ignore match weights when searching matched policysets 2020-05-29 12:52:54 +08:00
wanyaoqi
d90c2eef70 fix migrate with multi local storage 2020-05-29 11:55:19 +08:00
Zexi Li
fba3067090 Merge pull request #6624 from ioito/automated-cherry-pick-of-#6619-upstream-release-3.0
Automated cherry pick of #6619: fix: 避免azure卸载磁盘失败
2020-05-27 17:52:18 +08:00
Qu Xuan
6a5e6b2920 fix: 避免azure卸载磁盘失败 2020-05-27 15:57:21 +08:00
Zexi Li
e1bda8042e Merge pull request #6601 from wanyaoqi/automated-cherry-pick-of-#6598-upstream-release-3.0
Automated cherry pick of #6598: fix remotefile fetch image propertites
2020-05-26 17:15:26 +08:00
Zexi Li
ec587c668e Merge pull request #6597 from ioito/automated-cherry-pick-of-#6594-upstream-release-3.0
Automated cherry pick of #6594: fix: bucket信息修正
2020-05-26 17:14:20 +08:00
wanyaoqi
0f27e97b60 fix remotefile fetch image propertites 2020-05-26 15:55:24 +08:00
Qu Xuan
56efaf297d fix: bucket信息修正 2020-05-26 15:10:57 +08:00
Zexi Li
67b3bfe1d7 Merge pull request #6585 from zexi/automated-cherry-pick-of-#6584-upstream-release-3.0
Automated cherry pick of #6584: fix k8s repo wrong privilege
2020-05-25 18:28:12 +08:00
Zexi Li
e697c9a7a5 fix k8s repo wrong privilege 2020-05-25 16:59:45 +08:00
Zexi Li
ac23daea23 Merge pull request #6575 from zhaoxiangchun/automated-cherry-pick-of-#6573-upstream-release-3.0
Automated cherry pick of #6573: zstack宿主机监控中增加参数信息进行Unmarshal
2020-05-25 12:18:03 +08:00
zhaoxiangchun
0ab2b4fea6 zstack宿主机监控中增加参数信息进行Unmarshal 2020-05-24 17:18:52 +08:00
Zexi Li
7fc1319622 Merge pull request #6570 from swordqiu/automated-cherry-pick-of-#6567-upstream-release-3.0
Automated cherry pick of #6567: fix: default policy not effective
2020-05-22 22:48:41 +08:00
Zexi Li
87c538e3fa Merge pull request #6561 from ioito/automated-cherry-pick-of-#6558-upstream-release-3.0
Automated cherry pick of #6558: fix: 避免openstack以镜像做系统盘创建失败
2020-05-22 22:45:33 +08:00
Qiu Jian
b227baf505 fix: default policy not effective 2020-05-22 22:39:47 +08:00
Qu Xuan
010518b352 fix: 避免openstack以镜像做系统盘创建失败 2020-05-22 20:18:26 +08:00
Zexi Li
55528fc19e Merge pull request #6554 from swordqiu/automated-cherry-pick-of-#6551-upstream-release-3.0
Automated cherry pick of #6551: fix: empty matched policies list for roles
2020-05-22 19:32:46 +08:00
Qiu Jian
11d51cbab3 fix: empty matched policies list for roles 2020-05-22 18:57:15 +08:00
Zexi Li
b7b38cad6f Merge pull request #6539 from ioito/automated-cherry-pick-of-#6530-upstream-release-3.0
Automated cherry pick of #6530: fix: aliyun rds backup create fix
2020-05-22 12:36:39 +08:00
Qu Xuan
46c916098f fix: aliyun rds backup create fix 2020-05-22 10:32:23 +08:00
Zexi Li
12d76c782d Merge pull request #6514 from ioito/automated-cherry-pick-of-#6511-upstream-release-3.0
Automated cherry pick of #6511: fix: 避免忽略本地allow any云上deny any安全组规则同步
2020-05-22 10:22:47 +08:00
Zexi Li
cfbfda82f7 Merge pull request #6523 from swordqiu/automated-cherry-pick-of-#6516-upstream-release-3.0
Automated cherry pick of #6516: fix: system privileges user cannot access system console
2020-05-22 10:15:29 +08:00
yunion-ci-robot
473ae778ff Merge pull request #6520 from zexi/automated-cherry-pick-of-#6481-upstream-release-3.0
Automated cherry pick of #6481: region: fix get resource details panic
2020-05-21 23:31:50 +08:00
yunion-ci-robot
76671e0ba0 Merge pull request #6508 from ioito/automated-cherry-pick-of-#6505-upstream-release-3.0
Automated cherry pick of #6505: fix: 上传镜像为转换列表之外时,subformat状态异常
2020-05-21 23:05:58 +08:00
yunion-ci-robot
2e4be413be Merge pull request #6521 from zexi/automated-cherry-pick-of-#6491-upstream-release-3.0
Automated cherry pick of #6491: keystone: fix db not sync
2020-05-21 22:48:52 +08:00
Qiu Jian
e8898952b3 fix: system privileges user cannot access system console 2020-05-21 18:45:42 +08:00
Zexi Li
8bc6397142 keystone: fix db not sync 2020-05-21 18:44:41 +08:00
Zexi Li
28e726d847 region: fix get resource details panic 2020-05-21 18:44:13 +08:00
Qu Xuan
f96d39e9fc fix: 避免忽略本地allow any云上deny any安全组规则同步 2020-05-21 18:31:26 +08:00
Qu Xuan
52d299d227 fix: 上传镜像为转换列表之外时,subformat状态异常 2020-05-21 17:42:19 +08:00
Zexi Li
051de2f7ee Merge pull request #6488 from rainzm/automated-cherry-pick-of-#6487-upstream-release-3.0
Automated cherry pick of #6487: Fix/esxi
2020-05-21 16:33:05 +08:00
rainzm
28d3ed0d84 fix(esxi): Modify the disk size correctly when creating vm 2020-05-21 10:56:47 +08:00
rainzm
9962104c1b fix(esxi): Detach all disk first when deleting vm 2020-05-21 10:53:57 +08:00
rainzm
2708277112 Kill processes in time & Add debug info 2020-05-21 10:53:57 +08:00
rainzm
70d2acdc5d fix(esxi): Remove 'Destory' operation that is unnecessary for VirtualDiskManager 2020-05-21 10:53:57 +08:00
rainzm
3946fc2b74 fix(esxi): Separate detach disk and delete disk when rebuilding.
In previous versions, set
`removeSpec.FileOperation = types.VirtualDeviceConfigSpecFileOperationDestroy'
to delete disk indirectly.

But, when its parent has only one child, the parent will be deleted along with it.
And the consequence is failure to reinstall the system.

Now, detach disk without deleteing backing file and then remove backing
2020-05-21 10:53:57 +08:00
Zexi Li
9490fb2011 Merge pull request #6477 from yousong/bugfix/yousong-region-3.0
Bugfix/yousong region 3.0
2020-05-20 12:53:33 +08:00
Yousong Zhou
559e448459 wires: default to "default" vpc on creation
Wire creation request right now only makes sense in context of classic
network ("default" vpc)
2020-05-20 11:11:12 +08:00
Yousong Zhou
f63d10594e networks: eliminate a variable 2020-05-20 11:09:23 +08:00
Yousong Zhou
6093bf2eca guestdrivers: managed: use const api.EIP_STATUS_ASSOCIATE 2020-05-20 11:07:25 +08:00
Yousong Zhou
82b7b3ebe9 cloudprovider: fix typo 2020-05-20 11:07:24 +08:00
Yousong Zhou
cb65ca44f5 cloudcommon: rbac: fix typo 2020-05-20 11:07:24 +08:00
Zexi Li
f26e83de1b Merge pull request #6466 from zexi/automated-cherry-pick-of-#6462-upstream-release-3.0
Automated cherry pick of #6462: region: fix server create params not include specified resource
2020-05-19 19:09:00 +08:00
Zexi Li
ee778d68d6 region: fix server create params not include specified resource 2020-05-19 17:39:08 +08:00
Zexi Li
939d21c5a3 Merge pull request #6446 from swordqiu/automated-cherry-pick-of-#6443-upstream-release-3.0
Automated cherry pick of #6443: fix: anonymous user may list resources
2020-05-19 10:18:04 +08:00
Zexi Li
d2c008cbd9 Merge pull request #6438 from zexi/automated-cherry-pick-of-#6436-upstream-release-3.0
Automated cherry pick of #6436: baremetal: fix ssh put empty content file not created
2020-05-19 10:16:07 +08:00
Qiu Jian
b78dcfb5c3 fix: anonymous user may list resources 2020-05-19 01:26:32 +08:00
Zexi Li
901cf1aac4 Merge pull request #6426 from ioito/automated-cherry-pick-of-#6423-upstream-release-3.0
Automated cherry pick of #6423: fix: 避免仅同步一个region时,其余region状态变为准备中
2020-05-18 21:49:24 +08:00
Zexi Li
96b43a126d Merge pull request #6431 from ioito/automated-cherry-pick-of-#6428-upstream-release-3.0
Automated cherry pick of #6428: fix: 避免设置自动释放后磁盘的expired_at失效
2020-05-18 21:48:04 +08:00
Zexi Li
d37b6550d1 baremetal: fix ssh put empty content file not created 2020-05-18 21:45:41 +08:00
Qu Xuan
6ef689a183 fix: 避免设置自动释放后磁盘的expired_at失效 2020-05-18 20:09:21 +08:00
Qu Xuan
575545da50 fix: 避免仅同步一个region时,其余region状态变为准备中 2020-05-18 19:38:54 +08:00
Zexi Li
6627a3365e Merge pull request #6412 from zhaoxiangchun/automated-cherry-pick-of-#6410-upstream-release-3.0
Automated cherry pick of #6410: 修复无法获取vmware宿主机监控数据的问题
2020-05-17 14:16:54 +08:00
yunion-ci-robot
4cfd27a39f Merge pull request #6416 from rainzm/release/3.0
update vendor for release/3.0
2020-05-16 23:33:38 +08:00
rainzm
11d7b58886 update vendor 2020-05-16 21:40:42 +08:00
zhaoxiangchun
6bdca14dd9 修复无法获取vmware宿主机监控数据的问题 2020-05-16 21:21:44 +08:00
yunion-ci-robot
6f164905d8 Merge pull request #6391 from zexi/automated-cherry-pick-of-#6388-upstream-release-3.0
Automated cherry pick of #6388: region: fix baremetal can't enable public baremetal type network
2020-05-16 18:25:04 +08:00
Zexi Li
be14f22f17 Merge pull request #6398 from swordqiu/automated-cherry-pick-of-#6395-upstream-release-3.0
Automated cherry pick of #6395: fix: server-sync-fix-nics should return errors if vnics ip is not reachable on host
2020-05-16 17:45:00 +08:00
Zexi Li
1b7a646197 Merge pull request #6378 from rainzm/automated-cherry-pick-of-#6375-upstream-release-3.0
Automated cherry pick of #6375: Fix/esxi
2020-05-16 17:41:48 +08:00
Zexi Li
53a04060db region: fix baremetal can't enable public baremetal type network 2020-05-16 17:36:50 +08:00
Qiu Jian
79b38223e1 fix: server-sync-fix-nics should return errors if vnics ip is not reachable on host 2020-05-15 22:27:36 +08:00
rainzm
87bc30ba2a fix(esxi): Add usb to support mouse in vnc viewer 2020-05-15 21:39:42 +08:00
rainzm
9cb95cfc0a fix(esxi): Fix GetDriver and add driver log for vdisk.
In GetDriver, return 'name' directly if driverMap is empty.
2020-05-15 21:38:40 +08:00
rainzm
47db06ef4d fix(esxi): Set 'WindowsDefaultAdminUser' as true when deploy vm.
'WindowsDefaultAdminUser' means that the default admin account is
'Administrator' when deploy windows vm.
2020-05-15 21:37:19 +08:00
rainzm
8694d85611 fix(region): Set default value if rootdisk's driver is empty. 2020-05-15 21:37:19 +08:00
rainzm
dcb07fa598 fix(esxi): Disable automatically add host to the dvs 2020-05-15 21:37:19 +08:00
rainzm
5731072086 fix(esxi): Set 'IsInit' as true when rebuildroot
IsInit is true will cause cloudinit enable. When rebuilding root, if there is cloudinit service in the image, it will cover the initialization work we did on the rebuilding.
2020-05-15 21:37:19 +08:00
Zexi Li
c038a92dac Merge pull request #6382 from zexi/automated-cherry-pick-of-#6381-upstream-release-3.0
Automated cherry pick of #6381: scheduler: fix min counter get count not correct
2020-05-15 15:28:22 +08:00
Zexi Li
18b21748cb scheduler: fix min counter get count not correct 2020-05-15 15:05:28 +08:00
Zexi Li
4bcd817fa6 Merge pull request #6355 from zexi/automated-cherry-pick-of-#6353-upstream-release-3.0
Automated cherry pick of #6353: scheduler: filter disabled cloudprovider
2020-05-14 18:59:19 +08:00
Zexi Li
1aaf3085a4 Merge pull request #6341 from swordqiu/automated-cherry-pick-of-#6338-upstream-release-3.0
Automated cherry pick of #6338: fix: avoid using background context
2020-05-14 18:19:04 +08:00
Zexi Li
8303918c0e scheduler: filter disabled cloudprovider 2020-05-14 18:14:21 +08:00
Zexi Li
261976d90d Merge pull request #6350 from zexi/automated-cherry-pick-of-#6347-upstream-release-3.0
Automated cherry pick of #6347: scheduler: set schedtag default strategy if input empty
2020-05-14 17:49:27 +08:00
Zexi Li
01edd43400 scheduler: set schedtag default strategy if input empty 2020-05-14 17:26:53 +08:00
Qiu Jian
1eca2fc8ed fix: avoid using background context 2020-05-14 17:06:07 +08:00
yunion-ci-robot
6e7bcf05d4 Merge pull request #6322 from wanyaoqi/automated-cherry-pick-of-#6319-upstream-release-3.0
Automated cherry pick of #6319: do not close worker chan
2020-05-13 20:17:00 +08:00
wanyaoqi
ddc69e575d do not close worker chan
don't close worker chan after put work, will cause dead loop
2020-05-13 18:59:32 +08:00
Zexi Li
587aecde18 Merge pull request #6309 from ioito/automated-cherry-pick-of-#6306-upstream-release-3.0
Automated cherry pick of #6306: fix: openstack 安全组规则同步
2020-05-13 12:41:34 +08:00
Zexi Li
d25c879d1c Merge pull request #6295 from ioito/automated-cherry-pick-of-#6292-upstream-release-3.0
Automated cherry pick of #6292: fix: 优化openstack错误处理
2020-05-13 10:42:57 +08:00
Qu Xuan
98ddfda02b fix: openstack 安全组规则同步 2020-05-12 17:56:35 +08:00
Qu Xuan
55fc5d9be2 fix: 优化openstack错误处理 2020-05-12 14:09:55 +08:00
Zexi Li
cd82204a7f Merge pull request #6290 from yousong/automated-cherry-pick-of-#6287-upstream-release-3.0
Automated cherry pick of #6287: region: lbagent: undeploy: make it idempotent
2020-05-12 11:50:39 +08:00
Zexi Li
31cc718842 Merge pull request #6285 from yousong/automated-cherry-pick-of-#6282-upstream-release-3.0
Automated cherry pick of #6282: region: lbagents: fix deleting pending_deleted objects
2020-05-12 11:43:51 +08:00
Yousong Zhou
88b2e7fa0c region: lbagent: undeploy: make it idempotent
Both the following three can result in the same error message "Could not
find the requested service yunion-xx: host"

  -m systemd -a 'name=yunion-xx enabled=no state=stopped daemon_reload=yes'
  -m systemd -a 'name=yunion-xx enabled=no state=stopped daemon_reload=yes force=yes'
  -m service -a 'name=yunion-xx enabled=no state=stopped'

Use of ansibleplaybookv2 is overkill and can break console expectation.
Just turn to shell module for now
2020-05-12 10:39:40 +08:00
Yousong Zhou
14a0027ea6 region: lbagents: fix deleting pending_deleted objects
This was broken since the introduction of virtual object
2020-05-12 10:11:45 +08:00
Zexi Li
bb7926bccc Merge pull request #6273 from zexi/automated-cherry-pick-of-#6270-upstream-release-3.0
Automated cherry pick of #6270: scheduler: get region nil panic
2020-05-11 21:07:49 +08:00
Zexi Li
e51bb96d42 Merge pull request #6261 from ioito/automated-cherry-pick-of-#6258-upstream-release-3.0
Automated cherry pick of #6258: fix: 避免aliyun磁盘计费类型多次转换
2020-05-11 18:17:15 +08:00
Zexi Li
d03c255ddd scheduler: get region nil panic 2020-05-11 18:05:24 +08:00
Qu Xuan
33fda0e75a fix: 避免aliyun磁盘计费类型多次转换 2020-05-11 14:06:51 +08:00
Zexi Li
a1a4a03579 Merge pull request #6254 from swordqiu/automated-cherry-pick-of-#6252-upstream-release-3.0
Automated cherry pick of #6252: fix: panic when disk has no valid storage_id
2020-05-11 10:01:37 +08:00
Qiu Jian
03de2989cc fix: panic when disk has no valid storage_id 2020-05-11 02:57:20 +08:00
Zexi Li
2bc3e418c9 Merge pull request #6250 from wanyaoqi/automated-cherry-pick-of-#6247-upstream-release-3.0
Automated cherry pick of #6247: fix import from libvirt
2020-05-10 21:35:23 +08:00
Zexi Li
5bd3503a57 Merge pull request #6234 from tb365/automated-cherry-pick-of-#6232-upstream-release-3.0
Automated cherry pick of #6232: huawei network id fix
2020-05-10 21:33:35 +08:00
wanyaoqi
3f826aeb65 fix import from libvirt 2020-05-10 20:45:17 +08:00
Zexi Li
ea88c439ab Merge pull request #6245 from yousong/automated-cherry-pick-of-#6242-upstream-release-3.0
Automated cherry pick of #6242: disks: reword error message on bad DiskConfig struct
2020-05-10 11:29:16 +08:00
Yousong Zhou
ef5c87b268 disks: reword error message on bad DiskConfig struct 2020-05-10 00:19:07 +08:00
tangbin
b0f7661d97 huawei network id fix 2020-05-09 20:10:17 +08:00
Zexi Li
3832cf5569 Merge pull request #6228 from yousong/automated-cherry-pick-of-#6225-upstream-release-3.0
Automated cherry pick of #6225: apigateway: handlers: register cloudnet modules
2020-05-09 18:47:52 +08:00
Yousong Zhou
6736f26c97 apigateway: handlers: register cloudnet modules 2020-05-09 16:41:48 +08:00
Zexi Li
7370fbae2c Merge pull request #6187 from zhaoxiangchun/automated-cherry-pick-of-#6185-upstream-release-3.0
Automated cherry pick of #6185: 修复谷歌监控无法获取的问题
2020-05-07 17:21:28 +08:00
zhaoxiangchun
c748528323 修复谷歌监控无法获取的问题
直接返回调用RestAPI的json格式数据
2020-05-07 11:27:35 +08:00
Zexi Li
5796cbab2f Merge pull request #6171 from yousong/automated-cherry-pick-of-#6168-upstream-release-3.0
Automated cherry pick of #6168: dnsrecords: note that DnsRecordManager is a IAdminSharableVirtualModelManager
2020-05-07 11:23:24 +08:00
Zexi Li
72ce0c4999 Merge pull request #6177 from swordqiu/automated-cherry-pick-of-#6174-upstream-release-3.0
Automated cherry pick of #6174: fix: fail to fetch real client ip from httprequest
2020-05-07 11:16:31 +08:00
Qiu Jian
6ff01f6025 fix: fail to fetch real client ip from httprequest 2020-05-06 22:27:58 +08:00
Yousong Zhou
a9d2dfd1ed dnsrecords: allow updating only description
This commit includes the following changes

 - Eliminate unused arguments from validateModelData()
 - Remove "records" member of input data unconditionally
 - Allow updates to not include records related parameters, to allow
   updating only "description" without emitting "Empty record" error
2020-05-06 18:43:19 +08:00
Yousong Zhou
6aa03b2931 dnsrecords: note that DnsRecordManager is a IAdminSharableVirtualModelManager 2020-05-06 18:43:18 +08:00
yunion-ci-robot
4125b0e217 Merge pull request #6161 from zhaoxiangchun/automated-cherry-pick-of-#6158-upstream-release-3.0
Automated cherry pick of #6158: bugfix mem paginate
2020-05-06 15:44:44 +08:00
zhaoxiangchun
c8f0ee4475 bugfix mem paginate
通过totoal和offset 与limit比较确定最后返回数据
2020-05-06 11:05:15 +08:00
Zexi Li
459332cf72 Merge pull request #6156 from ioito/automated-cherry-pick-of-#6153-upstream-release-3.0
Automated cherry pick of #6153: fix: secgroupcache权限问题修复
2020-04-30 20:14:12 +08:00
Qu Xuan
3649a8521b fix: secgroupcache权限问题修复 2020-04-30 15:44:23 +08:00
Zexi Li
24d35cff50 Merge pull request #6130 from swordqiu/automated-cherry-pick-of-#6120-upstream-release-3.0
Automated cherry pick of #6120: fix: sysadmin can override policy violation check
2020-04-29 21:15:53 +08:00
Zexi Li
b52a606b70 Merge pull request #6133 from tb365/automated-cherry-pick-of-#6132-upstream-release-3.0
Automated cherry pick of #6132: fix: FindAnonymousStructPoint needs input as a pointer to struct
2020-04-29 19:29:44 +08:00
Qiu Jian
2100133a67 fix: FindAnonymousStructPoint needs input as a pointer to struct 2020-04-29 18:30:40 +08:00
Qiu Jian
e04850d990 fix: sysadmin can override policy violation check 2020-04-29 18:00:14 +08:00
Zexi Li
f9d43f6977 Merge pull request #6114 from swordqiu/automated-cherry-pick-of-#6111-upstream-release-3.0
Automated cherry pick of #6111: fix: prevent policy violation
2020-04-29 13:10:16 +08:00
Zexi Li
df94c1c844 Merge pull request #6098 from ioito/automated-cherry-pick-of-#6095-upstream-release-3.0
Automated cherry pick of #6095: fix: 普通用户可获取rds账号密码
2020-04-29 13:08:18 +08:00
Qiu Jian
412f6abdfa fix: prevent policy violation 2020-04-29 00:07:59 +08:00
yunion-ci-robot
297629da22 Merge pull request #6106 from ioito/automated-cherry-pick-of-#6103-upstream-release-3.0
Automated cherry pick of #6103: fix: 修复openstack存储同步问题
2020-04-28 23:37:35 +08:00
Qu Xuan
f01fb15375 fix: 修复openstack存储同步问题 2020-04-28 14:48:23 +08:00
Qu Xuan
2a1c3802cd fix: 普通用户可获取rds账号密码 2020-04-28 10:43:36 +08:00
Zexi Li
bd374ab962 Merge pull request #6071 from ioito/automated-cherry-pick-of-#6068-upstream-release-3.0
Automated cherry pick of #6068: fix: gcp use project name for cloudprovider
2020-04-27 16:03:29 +08:00
Qu Xuan
6232adda22 fix: gcp use project name for cloudprovider 2020-04-27 14:17:36 +08:00
Zexi Li
9384137bf7 Merge pull request #6065 from rainzm/automated-cherry-pick-of-#6062-upstream-release-3.0
Automated cherry pick of #6062: fix/notify: Add deadline for rpc client
2020-04-27 12:48:11 +08:00
Rain
5a1192601b fix/notify: Add deadline for rpc client 2020-04-27 10:44:57 +08:00
Zexi Li
3b25e37ad6 Merge pull request #6057 from swordqiu/automated-cherry-pick-of-#6006-upstream-release-3.0
Automated cherry pick of #6006: fix: resolve parameter name conflict in google cloud account create input
2020-04-26 23:04:04 +08:00
Qiu Jian
4352752ed0 fix: resolve parameter name conflict in google cloud account create input 2020-04-26 21:53:51 +08:00
Zexi Li
77c3071463 Merge pull request #6048 from tb365/automated-cherry-pick-of-#6042-upstream-release-3.0
Automated cherry pick of #6042: huawei elb cookie timeout fix
2020-04-26 21:06:31 +08:00
tangbin
36d9cb4315 aws elb health check type fix 2020-04-26 20:10:52 +08:00
tangbin
73338fb693 huawei elb cookie timeout fix 2020-04-26 20:10:52 +08:00
yunion-ci-robot
7d97eecc80 Merge pull request #6010 from swordqiu/automated-cherry-pick-of-#6008-upstream-release-3.0
Automated cherry pick of #6008: fix: GetOnPremiseNetworkOfIP should return underlay networks
2020-04-26 19:49:32 +08:00
Zexi Li
17d046ed3a Merge pull request #6031 from ioito/automated-cherry-pick-of-#6028-upstream-release-3.0
Automated cherry pick of #6028: fix: json unmarshal
2020-04-26 18:19:30 +08:00
Qu Xuan
05ae1a345b fix: json unmarshal 2020-04-26 15:52:35 +08:00
yunion-ci-robot
0b93b48c57 Merge pull request #6017 from zexi/automated-cherry-pick-of-#6014-upstream-release-3.0
Automated cherry pick of #6014: scheduler: fix network predicate get wrong free port
2020-04-26 00:30:31 +08:00
Zexi Li
1c5f35b07b scheduler: fix network predicate get wrong free port 2020-04-25 23:28:51 +08:00
Qiu Jian
e02fea3bd2 fix: GetOnPremiseNetworkOfIP should return underlay networks 2020-04-25 16:30:30 +08:00
Zexi Li
76ec5ebec4 Merge pull request #5998 from yousong/automated-cherry-pick-of-#5995-upstream-release-3.0
Automated cherry pick of #5995: lblistener: fix updating lblistener without backend_group field
2020-04-24 18:17:27 +08:00
Yousong Zhou
1a333c4cdb lblistener: fix updating lblistener without backend_group field
Fixes dd01610931 ("lblistener: allow setting http/https listener
backendgroup to empty")
2020-04-24 14:23:24 +08:00
Zexi Li
c5a6b2c988 Merge pull request #5968 from swordqiu/automated-cherry-pick-of-#5966-upstream-release-3.0
Automated cherry pick of #5966: supermicro redfish support
2020-04-23 09:54:39 +08:00
Qiu Jian
83e524e26d remote errors import 2020-04-23 09:30:49 +08:00
Qiu Jian
fdef0e4b51 supermicro redfish support 2020-04-23 09:29:57 +08:00
Zexi Li
198d88394c Merge pull request #5964 from swordqiu/automated-cherry-pick-of-#5961-upstream-release-3.0
Automated cherry pick of #5961: fix: clean pending usage caused by pre-validate-create-data
2020-04-23 00:03:22 +08:00
Zexi Li
eb330da807 Merge pull request #5923 from ioito/automated-cherry-pick-of-#5919-upstream-release-3.0
Automated cherry pick of #5919: fix: 非私有云同步region name
2020-04-22 23:59:53 +08:00
Zexi Li
aff6bf30ab Merge pull request #5934 from ioito/automated-cherry-pick-of-#5931-upstream-release-3.0
Automated cherry pick of #5931: fix: 转换非标准存储类型到lrs
2020-04-22 23:57:32 +08:00
Zexi Li
6a54cc8139 Merge pull request #5949 from tb365/automated-cherry-pick-of-#5945-upstream-release-3.0
Automated cherry pick of #5945: huawei elb sync vpc
2020-04-22 23:56:00 +08:00
Zexi Li
99bdbb37a9 Merge pull request #5953 from zexi/automated-cherry-pick-of-#5951-upstream-release-3.0
Automated cherry pick of #5951: baremetal: ensure power up add retries
2020-04-22 23:52:19 +08:00
Qiu Jian
5635dc65ce fix: clean pending usage caused by pre-validate-create-data 2020-04-22 23:48:54 +08:00
yunion-ci-robot
cae673bee9 Merge pull request #5940 from tb365/automated-cherry-pick-of-#5927-upstream-release-3.0
Automated cherry pick of #5927: remove aws invalid backendgroup
2020-04-22 23:05:06 +08:00
Zexi Li
da6b918399 baremetal: ensure power up add retries 2020-04-22 22:12:50 +08:00
tangbin
fcf1fbc3e8 huawei elb sync vpc 2020-04-22 20:31:11 +08:00
tangbin
033947c780 remove aws invalid backendgroup 2020-04-22 18:58:38 +08:00
Qu Xuan
91c807b4ef fix: 转换非标准存储类型到lrs 2020-04-22 18:54:26 +08:00
Qu Xuan
0f5655db69 fix: 非私有云同步region name 2020-04-22 18:00:26 +08:00
Zexi Li
430ce468ef Merge pull request #5909 from swordqiu/automated-cherry-pick-of-#5906-upstream-release-3.0
Automated cherry pick of #5906: fix: blacklist keystone reset admin password
2020-04-22 15:09:38 +08:00
Qiu Jian
2cd04a148c fix: blacklist keystone reset admin password 2020-04-22 15:03:39 +08:00
Zexi Li
aec1eb7409 Merge pull request #5892 from swordqiu/automated-cherry-pick-of-#5890-upstream-release-3.0
Automated cherry pick of #5890: fix: policy details should carry updated_at and created_at fields
2020-04-22 10:34:40 +08:00
Zexi Li
bf66f68ab4 Merge pull request #5897 from swordqiu/automated-cherry-pick-of-#5895-upstream-release-3.0
Automated cherry pick of #5895: fix: delete idp also delete users/groups in target domain
2020-04-22 10:34:03 +08:00
Zexi Li
53bbc81832 Merge pull request #5887 from ioito/automated-cherry-pick-of-#5884-upstream-release-3.0
Automated cherry pick of #5884: fix: 仅当变更domainId时才需要更新projectId
2020-04-22 10:32:43 +08:00
Qiu Jian
a3776d9f7e fix: delete idp also delete users/groups in target domain 2020-04-22 10:13:51 +08:00
Qiu Jian
0ee4ab61e0 fix: policy details should carry updated_at and created_at fields 2020-04-21 22:42:09 +08:00
Qu Xuan
cd7bc57647 fix: 仅当变更domainId时才需要更新projectId 2020-04-21 21:14:59 +08:00
Zexi Li
21e803237a Merge pull request #5867 from tb365/automated-cherry-pick-of-#5865-upstream-release-3.0
Automated cherry pick of #5865: lblis & lbbg & lbr & lbb create add fetch owner id
2020-04-20 20:51:19 +08:00
tangbin
07cd34b501 lblis & lbbg & lbr & lbb create add fetch owner id 2020-04-20 19:26:28 +08:00
Zexi Li
fc9237c5ec Merge pull request #5847 from swordqiu/automated-cherry-pick-of-#5845-upstream-release-3.0
Automated cherry pick of #5845: fix: cloudproviderregion sync ignore panic
2020-04-18 12:02:22 +08:00
Zexi Li
8c78a7627a Merge pull request #5842 from tb365/automated-cherry-pick-of-#5840-upstream-release-3.0
Automated cherry pick of #5840: aws elb create bugfix
2020-04-18 11:59:59 +08:00
Qiu Jian
199b1a2510 fix: cloudproviderregion sync ignore panic 2020-04-17 22:07:10 +08:00
TangBin
9b604cd353 huawei oss client bugfix 2020-04-17 20:47:06 +08:00
TangBin
90889695fe huawei oss client fix & huawei client init fix 2020-04-17 20:47:06 +08:00
tangbin
5149f507d4 aws elb create bugfix 2020-04-17 20:42:02 +08:00
Zexi Li
8c3338454e Merge pull request #5820 from swordqiu/automated-cherry-pick-of-#5818-upstream-release-3.0
Automated cherry pick of #5818: fix: non-redfish baremetal might support jnlp console
2020-04-17 00:05:10 +08:00
Zexi Li
f2c604fd70 Merge pull request #5827 from ioito/automated-cherry-pick-of-#5825-upstream-release-3.0
Automated cherry pick of #5825: fix: 尽量避免secgroup重名问题
2020-04-17 00:03:06 +08:00
Zexi Li
5075c6c471 Merge pull request #5834 from zhaoxiangchun/automated-cherry-pick-of-#5831-upstream-release-3.0
Automated cherry pick of #5831: 修复azure获取不到监控数据的问题
2020-04-17 00:01:17 +08:00
zhaoxiangchun
be5fcc57ca 修复azure获取不到监控数据的问题 2020-04-16 20:12:51 +08:00
Zexi Li
338f5dd681 Merge pull request #5807 from ioito/automated-cherry-pick-of-#5805-upstream-release-3.0
Automated cherry pick of #5805: fix: 优化rds sku list查询速度
2020-04-16 18:01:34 +08:00
Qu Xuan
f0e192f394 fix: 尽量避免secgroup重名问题 2020-04-16 16:41:07 +08:00
Qiu Jian
b94fc93304 fix: non-redfish baremetal might support jnlp console 2020-04-15 23:55:10 +08:00
Qu Xuan
d3ca6cd0a7 fix: 优化rds sku list查询速度 2020-04-15 18:02:16 +08:00
Zexi Li
7647330e24 Merge pull request #5802 from zexi/automated-cherry-pick-of-#5798-upstream-release-3.0
Automated cherry pick of #5798: climc: support k8s service v3.2
2020-04-15 10:38:11 +08:00
Zexi Li
c3f393b244 climc: support k8s service v3.2 2020-04-15 10:37:29 +08:00
Zexi Li
20f0ff7ae0 Merge pull request #5787 from ioito/automated-cherry-pick-of-#5785-upstream-release-3.0
Automated cherry pick of #5785: fix: 避免aliyun access key不可用时返回NotFoundError错误
2020-04-14 10:45:06 +08:00
Qu Xuan
8cedb0711b fix: 避免aliyun access key不可用时返回NotFoundError错误 2020-04-13 18:49:39 +08:00
Zexi Li
ae36b4ef51 Merge pull request #5771 from wanyaoqi/automated-cherry-pick-of-#5769-upstream-release-3.0
Automated cherry pick of #5769: fix host init generate network config
2020-04-13 11:28:56 +08:00
Zexi Li
3803377446 Merge pull request #5762 from tb365/automated-cherry-pick-of-#5759-upstream-release-3.0
Automated cherry pick of #5759: aws elb bugfix
2020-04-13 11:27:38 +08:00
tangbin
68b6259374 aws elb bugfix 2020-04-13 10:28:50 +08:00
Zexi Li
006436ad3f Merge pull request #5782 from swordqiu/automated-cherry-pick-of-#5780-upstream-release-3.0
Automated cherry pick of #5780: fix: host jnlp request fail for idrac9
2020-04-13 09:49:16 +08:00
Qiu Jian
0eaa58cd3e fix: host jnlp request fail for idrac9 2020-04-13 00:10:43 +08:00
yunion-ci-robot
baf91bfa63 Merge pull request #5776 from ioito/automated-cherry-pick-of-#5774-upstream-release-3.0
Automated cherry pick of #5774: fix: azure重装系统删除不必要的参数
2020-04-12 00:37:54 +08:00
Qu Xuan
dcbb72c042 fix: azure重装系统删除不必要的参数 2020-04-11 15:11:34 +08:00
Zexi Li
65edf1e4c8 Merge pull request #5754 from swordqiu/automated-cherry-pick-of-#5745-upstream-release-3.0
Automated cherry pick of #5745: feature: redfish support IDRAC9 baremetal
2020-04-11 13:12:33 +08:00
Zexi Li
9a0b008921 Merge pull request #5767 from yousong/automated-cherry-pick-of-#5765-upstream-release-3.0
Automated cherry pick of #5765: region: lbagent: vrrp.advert_int must be the same inside cluster
2020-04-11 13:04:55 +08:00
Yousong Zhou
737d42aea5 region: lbagent: vrrp.advert_int must be the same inside cluster 2020-04-10 15:55:35 +08:00
wanyaoqi
3a778c0ad2 fix host init generate network config 2020-04-10 15:50:12 +08:00
yunion-ci-robot
52e461dc86 Merge pull request #5742 from yousong/automated-cherry-pick-of-#5740-upstream-release-3.0
Automated cherry pick of #5740: region: lbagents: fix returning error when glob has no match
2020-04-10 09:52:42 +08:00
Qiu Jian
9ea831b4fe feature: redfish support IDRAC9 baremetal 2020-04-09 22:57:12 +08:00
Yousong Zhou
5b35704b62 region: lbagents: fix returning error when glob has no match 2020-04-09 11:08:27 +08:00
Zexi Li
0fa48e0af5 Merge pull request #5728 from tb365/automated-cherry-pick-of-#5726-upstream-release-3.0
Automated cherry pick of #5726: huawei&qcloud&huawei elb bugfix
2020-04-08 21:53:55 +08:00
Zexi Li
bbd0d5ea35 Merge pull request #5735 from swordqiu/automated-cherry-pick-of-#5733-upstream-release-3.0
Automated cherry pick of #5733: fix: idp log connected/disconnected event
2020-04-08 21:51:44 +08:00
Qiu Jian
32a2da0106 fix: idp log connected/disconnected event 2020-04-08 21:26:36 +08:00
tangbin
bba3d575d3 huawei&qcloud&huawei elb bugfix 2020-04-08 20:08:13 +08:00
Zexi Li
ca205ffe94 Merge pull request #5716 from swordqiu/automated-cherry-pick-of-#5714-upstream-release-3.0
Automated cherry pick of #5714: fix: decouple getUserInfo at apigateway from capabilities call
2020-04-08 02:26:14 +08:00
Qiu Jian
01d9cb4ccf fix: decouple getUserInfo at apigateway from capabilities call 2020-04-08 00:05:35 +08:00
455 changed files with 7937 additions and 26394 deletions

View File

@@ -1,3 +1,3 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/apigateway /opt/yunion/bin/apigateway

View File

@@ -1,3 +1,3 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/cloudevent /opt/yunion/bin/cloudevent

View File

@@ -1,3 +1,3 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/cloudnet /opt/yunion/bin/cloudnet

View File

@@ -1,3 +1,3 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/devtool /opt/yunion/bin/devtool

View File

@@ -1,4 +1,4 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
COPY ./build/esxi-agent/root/opt/ /opt/
ADD ./_output/bin/esxi-agent /opt/yunion/bin/esxi-agent

View File

@@ -1,3 +1,3 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/keystone /opt/yunion/bin/keystone

View File

@@ -1,4 +1,4 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/logger /opt/yunion/bin/logger

View File

@@ -1,4 +1,4 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
COPY ./build/notify/root/opt/ /opt/
ADD ./_output/bin/notify /opt/yunion/bin/notify

View File

@@ -7,7 +7,7 @@ ENV TZ Asia/Shanghai
RUN mkdir -p /opt/yunion/bin
RUN apk update && \
apk add --no-cache tzdata ca-certificates && \
apk add --no-cache tzdata curl busybox-extras tcpdump strace ca-certificates && \
rm -rf /var/cache/apk/*
RUN cp /usr/share/zoneinfo/Asia/Shanghai /etc/localtime

View File

@@ -1,4 +1,4 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
COPY ./build/region/root/opt/ /opt/
ADD ./_output/bin/region /opt/yunion/bin/region

View File

@@ -1,3 +1,3 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/region-dns /opt/yunion/bin/region-dns

View File

@@ -1,3 +1,3 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/s3gateway /opt/yunion/bin/s3gateway

View File

@@ -1,3 +1,3 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/scheduler /opt/yunion/bin/scheduler

View File

@@ -1,4 +1,4 @@
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:latest
FROM registry.cn-beijing.aliyuncs.com/yunionio/onecloud-base:v0.1
ADD ./_output/bin/yunionconf /opt/yunion/bin/yunionconf

View File

@@ -26,6 +26,28 @@ import (
"yunion.io/x/onecloud/pkg/mcclient/options"
)
func parseGcpCredential(filename string) (jsonutils.JSONObject, error) {
data, err := ioutil.ReadFile(filename)
if err != nil {
return nil, err
}
authParams, err := jsonutils.Parse(data)
if err != nil {
return nil, err
}
ret := jsonutils.NewDict()
for _, k := range []string{
"client_email",
"project_id",
"private_key_id",
"private_key",
} {
v, _ := authParams.Get(k)
ret.Add(v, fmt.Sprintf("gcp_%s", k))
}
return ret, nil
}
func init() {
type CloudaccountListOptions struct {
@@ -134,11 +156,7 @@ func init() {
R(&options.SGoogleCloudAccountCreateOptions{}, "cloud-account-create-google", "Create a Google cloud account", func(s *mcclient.ClientSession, args *options.SGoogleCloudAccountCreateOptions) error {
params := jsonutils.Marshal(args)
params.(*jsonutils.JSONDict).Add(jsonutils.NewString("Google"), "provider")
data, err := ioutil.ReadFile(args.GoogleJsonFile)
if err != nil {
return err
}
authParams, err := jsonutils.Parse(data)
authParams, err := parseGcpCredential(args.GoogleJsonFile)
if err != nil {
return err
}

View File

@@ -0,0 +1,9 @@
package k8s
import (
"yunion.io/x/onecloud/pkg/mcclient/modules/k8s"
)
func initEvent() {
initK8sNamespaceResource("event", k8s.Events)
}

View File

@@ -16,6 +16,11 @@ package k8s
import (
"fmt"
"io/ioutil"
"os"
"os/exec"
"github.com/ghodss/yaml"
"yunion.io/x/jsonutils"
@@ -57,7 +62,7 @@ func init() {
initPVC()
initJob()
initCronJob()
initEvent()
initRbac()
initApp()
@@ -217,6 +222,71 @@ func NewK8sNsResourceGetCmd(cmdN CmdNameFactory, manager modulebase.Manager) *Cm
)
}
func NewK8sNsResourceGetRawCmd(cmdN CmdNameFactory, manager k8s.IClusterResourceManager) *Cmd {
return NewCommand(
&o.NamespaceResourceGetOptions{},
cmdN.Do("show-raw"),
fmt.Sprintf("Show k8s %s raw data", cmdN.Kind),
func(s *mcclient.ClientSession, args *o.NamespaceResourceGetOptions) error {
ret, err := manager.GetRaw(s, args.NAME, args.Params())
if err != nil {
return err
}
printObjectYAML(ret)
return nil
},
)
}
func NewK8sResourceEditRawCmd(cmdN CmdNameFactory, manager k8s.IClusterResourceManager) *Cmd {
return NewCommand(
&o.NamespaceResourceGetOptions{},
cmdN.Do("edit-raw"),
fmt.Sprintf("Edit and update k8s %s raw data", cmdN.Kind),
func(s *mcclient.ClientSession, args *o.NamespaceResourceGetOptions) error {
rawData, err := manager.GetRaw(s, args.NAME, args.Params())
if err != nil {
return err
}
yamlBytes := rawData.YAMLString()
tempfile, err := ioutil.TempFile("", fmt.Sprintf("k8s-%s-%s*.yaml", cmdN.Kind, args.NAME))
if err != nil {
return err
}
defer os.Remove(tempfile.Name())
if _, err := tempfile.Write([]byte(yamlBytes)); err != nil {
return err
}
if err := tempfile.Close(); err != nil {
return err
}
cmd := exec.Command("vim", tempfile.Name())
cmd.Stdin = os.Stdin
cmd.Stdout = os.Stdout
if err := cmd.Run(); err != nil {
return err
}
content, err := ioutil.ReadFile(tempfile.Name())
if err != nil {
return err
}
jsonBytes, err := yaml.YAMLToJSON(content)
if err != nil {
return err
}
body, err := jsonutils.Parse(jsonBytes)
if err != nil {
return err
}
if _, err := manager.UpdateRaw(s, args.NAME, args.Params(), body.(*jsonutils.JSONDict)); err != nil {
return err
}
return nil
},
)
}
func NewK8sResourceDeleteCmd(cmdN CmdNameFactory, manager modulebase.Manager) *Cmd {
return NewCommand(
&o.ResourceDeleteOptions{},
@@ -244,11 +314,13 @@ func NewK8sNsResourceDeleteCmd(cmdN CmdNameFactory, manager modulebase.Manager)
return deleteCmd
}
func initK8sNamespaceResource(kind string, manager modulebase.Manager) *ShellCommands {
func initK8sNamespaceResource(kind string, manager k8s.IClusterResourceManager) *ShellCommands {
cmdN := NewCmdNameFactory(kind)
return NewShellCommands(cmdN.Do).AddR(
NewK8sNsResourceListCmd(cmdN, manager),
NewK8sNsResourceGetCmd(cmdN, manager),
NewK8sNsResourceDeleteCmd(cmdN, manager),
NewK8sNsResourceGetRawCmd(cmdN, manager),
NewK8sResourceEditRawCmd(cmdN, manager),
)
}

View File

@@ -134,7 +134,7 @@ func init() {
return nil
}
R(&PolicyPatchOptions{}, "policy-patch", "Patch policy", updateFunc)
R(&PolicyPatchOptions{}, "policy-update", "Patch policy", updateFunc)
R(&PolicyPatchOptions{}, "policy-update", "Update policy", updateFunc)
type PolicyPerformOptions struct {
ID string `help:"ID of policy to update"`
@@ -285,12 +285,30 @@ func init() {
if err != nil {
log.Fatalf("Set log level %q: %v", "debug", err)
}
if args.Debug {
rbacutils.ShowMatchRuleDebug = true
}
auth.InitFromClientSession(s)
policy.EnableGlobalRbac(15*time.Second, 15*time.Second, false)
if args.Debug {
consts.EnableRbacDebug()
}
findPolicy := false
for !findPolicy {
all := policy.PolicyManager.AllPolicies()
for _, allP := range all {
if len(allP) > 0 {
findPolicy = true
break
}
}
if findPolicy {
break
}
time.Sleep(time.Second)
}
req := jsonutils.NewDict()
for i := 0; i < len(args.Request); i += 1 {
parts := strings.Split(args.Request[i], ":")
@@ -356,6 +374,7 @@ func init() {
Context: mcclient.SAuthContext{
Ip: args.Ip,
},
Token: "faketoken",
}
} else {
token = s.GetToken()
@@ -367,6 +386,10 @@ func init() {
}
printObject(result)
for _, r := range args.Role {
fmt.Println("role", r, "matched policies:", policy.PolicyManager.RoleMatchPolicies(r))
}
fmt.Println("userCred:", token)
for _, scope := range []rbacutils.TRbacScope{
rbacutils.ScopeSystem,
@@ -375,7 +398,7 @@ func init() {
rbacutils.ScopeUser,
rbacutils.ScopeNone,
} {
m := policy.PolicyManager.MatchedPolicies(scope, token)
m := policy.PolicyManager.MatchedPolicyNames(scope, token)
fmt.Println("matched", scope, "policies:", m)
}

View File

@@ -987,6 +987,7 @@ func init() {
config.Hosts[i].HostIp = yamlConfig.Hosts[i].HostIp
config.Hosts[i].XmlFilePath = yamlConfig.Hosts[i].XmlFilePath
config.Hosts[i].Servers = make([]compute.SLibvirtServerConfig, len(yamlConfig.Hosts[i].Servers))
config.Hosts[i].MonitorPath = yamlConfig.Hosts[i].MonitorPath
for j := 0; j < len(yamlConfig.Hosts[i].Servers); j++ {
config.Hosts[i].Servers[j].MacIp = make(map[string]string)
mac := yamlConfig.Hosts[i].Servers[j].Mac
@@ -1009,11 +1010,11 @@ func init() {
if err != nil {
return err
}
for i := 0; i < len(params); i++ {
val := jsonutils.NewDict()
val.Set(modules.Servers.KeywordPlural, params[i])
params[i] = val
}
//for i := 0; i < len(params); i++ {
// val := jsonutils.NewDict()
// val.Set(modules.Servers.KeywordPlural, params[i])
// params[i] = val
//}
results := modules.Servers.BatchPerformClassAction(s, "import-from-libvirt", params)
printBatchResults(results, modules.Servers.GetColumns(s))

12
go.mod
View File

@@ -3,7 +3,7 @@ module yunion.io/x/onecloud
go 1.12
require (
cloud.google.com/go v0.38.0
cloud.google.com/go v0.38.0 // indirect
github.com/360EntSecGroup-Skylar/excelize v1.4.0
github.com/Azure/azure-sdk-for-go v36.1.0+incompatible
github.com/Azure/go-autorest v10.15.5+incompatible
@@ -122,7 +122,7 @@ require (
golang.org/x/sync v0.0.0-20190423024810-112230192c58
golang.org/x/sys v0.0.0-20191008105621-543471e840be
golang.zx2c4.com/wireguard/wgctrl v0.0.0-20191008142428-8d021180e987
google.golang.org/api v0.13.0 // indirect
google.golang.org/appengine v1.5.0 // indirect
google.golang.org/genproto v0.0.0-20190502173448-54afdca5d873
google.golang.org/grpc v1.23.1
gopkg.in/asn1-ber.v1 v1.0.0-20181015200546-f715ec2f112d // indirect
@@ -138,12 +138,12 @@ require (
k8s.io/klog v0.1.0 // indirect
k8s.io/kubernetes v1.12.3
yunion.io/x/executor v0.0.0-20200227030256-a18417815e74
yunion.io/x/jsonutils v0.0.0-20200303051356-aa609aba0cda
yunion.io/x/log v0.0.0-20190629062853-9f6483a7103d
yunion.io/x/pkg v0.0.0-20200304112442-9dae9351325e
yunion.io/x/jsonutils v0.0.0-20200415132054-2bf8a5e94501
yunion.io/x/log v0.0.0-20200313080802-57a4ce5966b3
yunion.io/x/pkg v0.0.0-20200516092703-0a53bc9270aa
yunion.io/x/s3cli v0.0.0-20190917004522-13ac36d8687e
yunion.io/x/sqlchemy v0.0.0-20200312002602-1177cd8fbc57
yunion.io/x/structarg v0.0.0-20190809075558-115bed041de3
yunion.io/x/structarg v0.0.0-20200423163001-168d0687be7e
)
replace github.com/ceph/go-ceph v0.0.0-20181217221554-e32f9f0f2e94 => github.com/yunionio/go-ceph v0.0.0-20190912101231-6f05a06b3859

26
go.sum
View File

@@ -226,8 +226,6 @@ github.com/google/uuid v1.1.0 h1:Jf4mxPC/ziBnoPIdpQdPJ9OeiomAUHLvxmPRSPH9m4s=
github.com/google/uuid v1.1.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
github.com/googleapis/gax-go/v2 v2.0.4 h1:hU4mGcQI4DaAYW+IbTun+2qEZVFxK0ySjQLTbS0VQKc=
github.com/googleapis/gax-go/v2 v2.0.4/go.mod h1:0Wqv26UfaUD9n4G6kQubkQ+KchISgw+vpHVxEJEs9eg=
github.com/googleapis/gax-go/v2 v2.0.5 h1:sjZBwGj9Jlw33ImPtvFviGYvseOtDM7hkSKB7+Tv3SM=
github.com/googleapis/gax-go/v2 v2.0.5/go.mod h1:DWXyrwAJ9X0FpwwEdw+IPEYBICEFu5mhpdKc/us6bOk=
github.com/googleapis/gnostic v0.2.0 h1:l6N3VoaVzTncYYW+9yOz2LJJammFZGBO13sqgEhpy9g=
github.com/googleapis/gnostic v0.2.0/go.mod h1:sJBsCZ4ayReDTBIg8b9dl28c5xFWyhBTVRp3pOg5EKY=
github.com/googollee/go-engine.io v0.0.0-20180829091931-e2f255711dcb h1:n22Aukg/TjoypWc37dbKIpCsz0VMFPD36HQk1WKvg3A=
@@ -263,8 +261,6 @@ github.com/hako/durafmt v0.0.0-20180520121703-7b7ae1e72ead h1:Y9WOGZY2nw5ksbEf5A
github.com/hako/durafmt v0.0.0-20180520121703-7b7ae1e72ead/go.mod h1:5Scbynm8dF1XAPwIwkGPqzkM/shndPm79Jd1003hTjE=
github.com/hashicorp/golang-lru v0.5.0 h1:CL2msUPvZTLb5O648aiLNJw3hnBxN2+1Jq8rCOH9wdo=
github.com/hashicorp/golang-lru v0.5.0/go.mod h1:/m3WP610KZHVQ1SGc6re/UDhFvYD7pJ4Ao+sR/qLZy8=
github.com/hashicorp/golang-lru v0.5.1 h1:0hERBMJE1eitiLkihrMvRVBYAkpHzc/J3QdDN+dAcgU=
github.com/hashicorp/golang-lru v0.5.1/go.mod h1:/m3WP610KZHVQ1SGc6re/UDhFvYD7pJ4Ao+sR/qLZy8=
github.com/hpcloud/tail v1.0.0/go.mod h1:ab1qPbhIpdTxEkNHXyeSf5vhxWSCs/tWer42PpOxQnU=
github.com/huandu/xstrings v1.0.0/go.mod h1:4qWG/gcEcfX4z/mBDHJ++3ReCw9ibxbsNJbcucJdbSo=
github.com/huandu/xstrings v1.2.0 h1:yPeWdRnmynF7p+lLYz0H2tthW9lqhMJrQV/U7yy4wX0=
@@ -539,7 +535,6 @@ golang.org/x/lint v0.0.0-20181026193005-c67002cb31c3/go.mod h1:UVdnD1Gm6xHRNCYTk
golang.org/x/lint v0.0.0-20190227174305-5b3e6a55c961/go.mod h1:wehouNa3lNwaWXcvxsM5YxQ5yQlVC4a0KAMCusXpPoU=
golang.org/x/lint v0.0.0-20190301231843-5614ed5bae6f/go.mod h1:UVdnD1Gm6xHRNCYTkRU2/jEulfH38KcIWyp/GAMgvoE=
golang.org/x/lint v0.0.0-20190313153728-d0100b6bd8b3/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc=
golang.org/x/lint v0.0.0-20190409202823-959b441ac422/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc=
golang.org/x/net v0.0.0-20180524181706-dfa909b99c79/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
golang.org/x/net v0.0.0-20180724234803-3673e40ba225/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
golang.org/x/net v0.0.0-20180826012351-8a410e7b638d/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
@@ -553,7 +548,6 @@ golang.org/x/net v0.0.0-20190311183353-d8887717615a/go.mod h1:t9HGtf8HONx5eT2rtn
golang.org/x/net v0.0.0-20190313220215-9f648a60d977/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
golang.org/x/net v0.0.0-20190419010253-1f3472d942ba/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
golang.org/x/net v0.0.0-20190503192946-f4e77d36d62c/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
golang.org/x/net v0.0.0-20190522155817-f3200d17e092/go.mod h1:HSz+uSET+XFnRR8LxR5pz3Of3rY3CfYBVs4xY44aLks=
golang.org/x/net v0.0.0-20190603091049-60506f45cf65 h1:+rhAzEzT3f4JtomfC371qB+0Ola2caSKcY69NUBZrRQ=
golang.org/x/net v0.0.0-20190603091049-60506f45cf65/go.mod h1:HSz+uSET+XFnRR8LxR5pz3Of3rY3CfYBVs4xY44aLks=
@@ -591,7 +585,6 @@ golang.org/x/sys v0.0.0-20190411185658-b44545bcd369/go.mod h1:h1NjWce9XRLGQEsW7w
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20190418153312-f0ce4c0180be/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20190422165155-953cdadca894/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20190507160741-ecd444e8653b/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20190606122018-79a91cf218c4/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20190826190057-c7b8b68b1456/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20190830023255-19e00faab6ad/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
@@ -615,7 +608,6 @@ golang.org/x/tools v0.0.0-20190226205152-f727befe758c/go.mod h1:9Yl7xja0Znq3iFh3
golang.org/x/tools v0.0.0-20190311212946-11955173bddd/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs=
golang.org/x/tools v0.0.0-20190312170243-e65039ee4138/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs=
golang.org/x/tools v0.0.0-20190328211700-ab21143f2384/go.mod h1:LCzVGOaR6xXOjkQ3onu1FJEFr0SW1gC7cKk1uF8kGRs=
golang.org/x/tools v0.0.0-20190506145303-2d16b83fe98c/go.mod h1:RgjU9mgBXZiqYHBnxXauZ1Gv1EHHAz9KjViQ78xBX0Q=
golang.org/x/tools v0.0.0-20190524140312-2c0ae7006135 h1:5Beo0mZN8dRzgrMMkDp0jc8YXQKx9DiJ2k1dkvGsn5A=
golang.org/x/tools v0.0.0-20190524140312-2c0ae7006135/go.mod h1:RgjU9mgBXZiqYHBnxXauZ1Gv1EHHAz9KjViQ78xBX0Q=
golang.zx2c4.com/wireguard v0.0.20190908 h1:SUoXDdwSMtomLdvke+zz83/u9tNvl4hHmcTIWp38tow=
@@ -625,8 +617,6 @@ golang.zx2c4.com/wireguard/wgctrl v0.0.0-20191008142428-8d021180e987/go.mod h1:7
google.golang.org/api v0.3.1 h1:oJra/lMfmtm13/rgY/8i3MzjFWYXvQIAKjQ3HqofMk8=
google.golang.org/api v0.3.1/go.mod h1:6wY9I6uQWHQ8EM57III9mq/AjF+i8G65rmVagqKMtkk=
google.golang.org/api v0.4.0/go.mod h1:8k5glujaEP+g9n7WNsDg8QP6cUVNI86fCNMcbazEtwE=
google.golang.org/api v0.13.0 h1:Q3Ui3V3/CVinFWFiW39Iw0kMuVrRzYX0wN6OPFp0lTA=
google.golang.org/api v0.13.0/go.mod h1:iLdEw5Ide6rF15KTC1Kkl0iskquN2gFfn9o9XIsbkAI=
google.golang.org/appengine v1.1.0/go.mod h1:EbEs0AVv82hx2wNQdGPgUI5lhzA/G0D9YwlJXL52JkM=
google.golang.org/appengine v1.4.0 h1:/wp5JvzpHIxhs/dumFmF7BXTf3Z+dd4uXta4kVyO508=
google.golang.org/appengine v1.4.0/go.mod h1:xpcJRLb0r/rnEns0DIKYYv+WjYCduHsrkT7/EB5XEv4=
@@ -642,7 +632,6 @@ google.golang.org/genproto v0.0.0-20190502173448-54afdca5d873/go.mod h1:VzzqZJRn
google.golang.org/grpc v1.17.0/go.mod h1:6QZJwpn2B+Zp71q/5VxRsJ6NXXVCE5NRUHRo+f3cWCs=
google.golang.org/grpc v1.19.0 h1:cfg4PD8YEdSFnm7qLV4++93WcmhH2nIUhMjhdCvl3j8=
google.golang.org/grpc v1.19.0/go.mod h1:mqu4LbDTu4XGKhr4mRzUsmM4RtVoemTSY81AxZiDr8c=
google.golang.org/grpc v1.20.1/go.mod h1:10oTOabMzJvdu6/UiuZezV6QK5dSlG84ov/aaiqXj38=
google.golang.org/grpc v1.22.0/go.mod h1:Y5yQAOtifL1yxbo5wqy6BxZv8vAUGQwXBOALyacEbxg=
google.golang.org/grpc v1.23.1 h1:q4XQuHFC6I28BKZpo6IYyb3mNO+l7lSOxRuYTCiDfXk=
google.golang.org/grpc v1.23.1/go.mod h1:Y5yQAOtifL1yxbo5wqy6BxZv8vAUGQwXBOALyacEbxg=
@@ -676,7 +665,6 @@ gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
honnef.co/go/tools v0.0.0-20180728063816-88497007e858/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
honnef.co/go/tools v0.0.0-20190106161140-3f1c8253044a/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
honnef.co/go/tools v0.0.0-20190418001031-e561f6794a2a/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
honnef.co/go/tools v0.0.0-20190523083050-ea95bdfd59fc/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
k8s.io/api v0.0.0-20181004124137-fd83cbc87e76 h1:cGc6jt7tNK7a2WfgNKjxjoU/UXXr9Q7JTqvCupZ+6+Y=
k8s.io/api v0.0.0-20181004124137-fd83cbc87e76/go.mod h1:iuAfoD4hCxJ8Onx9kaTIt30j7jUFS00AXQi6QMi99vA=
@@ -694,21 +682,23 @@ yunion.io/x/executor v0.0.0-20200227030256-a18417815e74 h1:A15C6VdVRWvmQ9pAJHrUs
yunion.io/x/executor v0.0.0-20200227030256-a18417815e74/go.mod h1:Uxuou9WQIeJXNpy7t2fPLL0BYLvLiMvGQwY7Qc6aSws=
yunion.io/x/jsonutils v0.0.0-20190625054549-a964e1e8a051 h1:vtZw2iwGrsARNSwRTREGjmr2BWPdxbmXVkb3kI1qu28=
yunion.io/x/jsonutils v0.0.0-20190625054549-a964e1e8a051/go.mod h1:4N0/RVzsYL3kH3WE/H1BjUQdFiWu50JGCFQuuy+Z634=
yunion.io/x/jsonutils v0.0.0-20200303051356-aa609aba0cda h1:wSwQj3MDGchGYM2RAo1riYhrTz4apH+5XyBnchuDi84=
yunion.io/x/jsonutils v0.0.0-20200303051356-aa609aba0cda/go.mod h1:T7kxQJR13+t7z0TuT+Wzd7MTxBOk2H9c0pO1ONQSv90=
yunion.io/x/jsonutils v0.0.0-20200415132054-2bf8a5e94501 h1:i1r9XvbdxH3FgTCLmTaRi3MzQqhiQimXJRlUOPgrxnU=
yunion.io/x/jsonutils v0.0.0-20200415132054-2bf8a5e94501/go.mod h1:T7kxQJR13+t7z0TuT+Wzd7MTxBOk2H9c0pO1ONQSv90=
yunion.io/x/log v0.0.0-20190514041436-04ce53b17c6b h1:Z9z+7iegu0HXuL+S8taVWRd1P4b9JJOgPXIeoqYrj7c=
yunion.io/x/log v0.0.0-20190514041436-04ce53b17c6b/go.mod h1:+gauLs73omeJAPlsXcevLsJLKixV+sR/E7WSYTSx1fE=
yunion.io/x/log v0.0.0-20190629062853-9f6483a7103d h1:59zrDL7Ft+hDukguJRmLr/Gdu/9V75x+yX99ovZwfaA=
yunion.io/x/log v0.0.0-20190629062853-9f6483a7103d/go.mod h1:LC6f/4FozL0iaAbnFt2eDX9jlsyo3WiOUPm03d7+U4U=
yunion.io/x/log v0.0.0-20200313080802-57a4ce5966b3 h1:5Wc5hkB8PtMudmHuzCyok960RuOa9I55imIGrigSdjs=
yunion.io/x/log v0.0.0-20200313080802-57a4ce5966b3/go.mod h1:LC6f/4FozL0iaAbnFt2eDX9jlsyo3WiOUPm03d7+U4U=
yunion.io/x/pkg v0.0.0-20190620104149-945c25821dbf h1:OsKC+2ghZHwp+Ztm/MwKlLKKRiE7QcPG8eTp0GmsHbg=
yunion.io/x/pkg v0.0.0-20190620104149-945c25821dbf/go.mod h1:t6rEGG2sQ4J7DhFxSZVOTjNd0YO/KlfWQyK1W4tog+E=
yunion.io/x/pkg v0.0.0-20190628082551-f4033ba2ea30/go.mod h1:t6rEGG2sQ4J7DhFxSZVOTjNd0YO/KlfWQyK1W4tog+E=
yunion.io/x/pkg v0.0.0-20200302034534-fdf44d54b070/go.mod h1:t6rEGG2sQ4J7DhFxSZVOTjNd0YO/KlfWQyK1W4tog+E=
yunion.io/x/pkg v0.0.0-20200304112442-9dae9351325e h1:rBfX77+VEBVpe6Xxy2gDa4WB7qbtndWvXcrVKzleF84=
yunion.io/x/pkg v0.0.0-20200304112442-9dae9351325e/go.mod h1:t6rEGG2sQ4J7DhFxSZVOTjNd0YO/KlfWQyK1W4tog+E=
yunion.io/x/pkg v0.0.0-20200516092703-0a53bc9270aa h1:VizPfW8+mLFEE7W/97zxQJbfdxchi2dn1M/Y7YBwTTc=
yunion.io/x/pkg v0.0.0-20200516092703-0a53bc9270aa/go.mod h1:t6rEGG2sQ4J7DhFxSZVOTjNd0YO/KlfWQyK1W4tog+E=
yunion.io/x/s3cli v0.0.0-20190917004522-13ac36d8687e h1:v+EzIadodSwkdZ/7bremd7J8J50Cise/HCylsOJngmo=
yunion.io/x/s3cli v0.0.0-20190917004522-13ac36d8687e/go.mod h1:0iFKpOs1y4lbCxeOmq3Xx/0AcQoewVPwj62eRluioEo=
yunion.io/x/sqlchemy v0.0.0-20200312002602-1177cd8fbc57 h1:KtQAuLJ00RSUVqkiRmJ1DiDABiw0U3xxXnzD3lGavaY=
yunion.io/x/sqlchemy v0.0.0-20200312002602-1177cd8fbc57/go.mod h1:FTdwPdGhMgh4E+UFXc9klI1Ok34fMuybTT+jLhOaIjI=
yunion.io/x/structarg v0.0.0-20190809075558-115bed041de3 h1:bfC8EhXYvyGYldRWlzxiCM39Zfj3s3+zham9mW2h2LE=
yunion.io/x/structarg v0.0.0-20190809075558-115bed041de3/go.mod h1:EP6NSv2C0zzqBDTKumv8hPWLb3XvgMZDHQRfyuOrQng=
yunion.io/x/structarg v0.0.0-20200423163001-168d0687be7e h1:pctCe/EPel3F1B83pJ2q9b34Umd1NdbLW1Yd+Lzur2s=
yunion.io/x/structarg v0.0.0-20200423163001-168d0687be7e/go.mod h1:EP6NSv2C0zzqBDTKumv8hPWLb3XvgMZDHQRfyuOrQng=

View File

@@ -29,6 +29,7 @@ import (
"yunion.io/x/onecloud/pkg/apigateway/constants"
"yunion.io/x/onecloud/pkg/apigateway/options"
policytool "yunion.io/x/onecloud/pkg/apigateway/policy"
"yunion.io/x/onecloud/pkg/apis/compute"
"yunion.io/x/onecloud/pkg/appctx"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/cloudcommon/policy"
@@ -360,7 +361,7 @@ func isUserAllowWebconsole(ctx context.Context, w http.ResponseWriter, req *http
return false
}
if !jsonutils.QueryBoolean(usr, "allow_web_console", true) {
httperrors.ForbiddenError(w, "forbidden user %q login from web", usr.String())
httperrors.ForbiddenError(w, "user forbidden login from web")
return false
}
return true
@@ -569,6 +570,7 @@ func (this *projectRoles) add(roleId, roleName string) {
func (this *projectRoles) getToken(scope rbacutils.TRbacScope, user, userId, domain, domainId string, ip string) mcclient.TokenCredential {
return &mcclient.SSimpleToken{
Token: "faketoken",
Domain: domain,
DomainId: domainId,
User: user,
@@ -608,12 +610,12 @@ func (this *projectRoles) json(user, userId, domain, domainId string, ip string)
}
obj.Add(roles, "roles")
for _, scope := range []rbacutils.TRbacScope{
rbacutils.ScopeSystem,
rbacutils.ScopeDomain,
rbacutils.ScopeProject,
rbacutils.ScopeDomain,
rbacutils.ScopeSystem,
} {
token := this.getToken(scope, user, userId, domain, domainId, ip)
matches := policy.PolicyManager.MatchedPolicies(scope, token)
matches := policy.PolicyManager.MatchedPolicyNames(scope, token)
obj.Add(jsonutils.NewStringArray(matches), fmt.Sprintf("%s_policies", scope))
if len(matches) > 0 {
obj.Add(jsonutils.JSONTrue, fmt.Sprintf("%s_capable", scope))
@@ -646,8 +648,11 @@ func getUserAuthCookie(ctx context.Context, s *mcclient.ClientSession, token mcc
}
func getLBAgentInfo(s *mcclient.ClientSession, token mcclient.TokenCredential) (*jsonutils.JSONDict, error) {
lbagents, err := modules.LoadbalancerAgents.List(s, nil)
params := jsonutils.NewDict()
params.Add(jsonutils.NewString("hb_last_seen.isnotempty()"), "filter.0")
params.Add(jsonutils.NewInt(1), "limit")
params.Add(jsonutils.JSONFalse, "details")
lbagents, err := modules.LoadbalancerAgents.List(s, params)
if err != nil {
return nil, errors.Wrapf(err, "user %s get lbagent", token.GetUserName())
}
@@ -665,6 +670,7 @@ func getLBAgentInfo(s *mcclient.ClientSession, token mcclient.TokenCredential) (
}
func getUserInfo(ctx context.Context, s *mcclient.ClientSession, token mcclient.TokenCredential, req *http.Request) (*jsonutils.JSONDict, error) {
log.Infof("getUserInfo modules.UsersV3.Get")
usr, err := modules.UsersV3.Get(s, token.GetUserId(), nil)
if err != nil {
log.Errorf("modules.UsersV3.Get fail %s", err)
@@ -693,6 +699,7 @@ func getUserInfo(ctx context.Context, s *mcclient.ClientSession, token mcclient.
data.Add(jsonutils.NewString(token.GetProjectDomain()), "projectDomain")
data.Add(jsonutils.NewString(token.GetProjectDomainId()), "projectDomainId")
log.Infof("getUserInfo modules.RoleAssignments.List")
query := jsonutils.NewDict()
query.Add(jsonutils.JSONNull, "effective")
query.Add(jsonutils.JSONNull, "include_names")
@@ -735,7 +742,7 @@ func getUserInfo(ctx context.Context, s *mcclient.ClientSession, token mcclient.
rbacutils.ScopeDomain,
rbacutils.ScopeProject,
} {
p := policy.PolicyManager.MatchedPolicies(scope, token)
p := policy.PolicyManager.MatchedPolicyNames(scope, token)
data.Add(jsonutils.NewStringArray(p), fmt.Sprintf("%s_policies", scope))
if scope == rbacutils.ScopeSystem {
data.Add(jsonutils.NewStringArray(p), "admin_policies")
@@ -772,6 +779,7 @@ func getUserInfo(ctx context.Context, s *mcclient.ClientSession, token mcclient.
log.Errorf("fail to find services????: %#v %s", adminToken, curReg)
}
log.Infof("getUserInfo getLBAgentInfo")
lb, err := getLBAgentInfo(s, adminToken)
if err != nil {
log.Errorf("getLBAgentInfo fail %s", err)
@@ -788,13 +796,23 @@ func getUserInfo(ctx context.Context, s *mcclient.ClientSession, token mcclient.
}
}
log.Infof("getUserInfo modules.Hosts.Get")
s2 := auth.GetSession(ctx, token, FetchRegion(req), "v2")
cap, err := modules.Capabilities.List(s2, nil)
params := jsonutils.NewDict()
params.Add(jsonutils.NewString("host_type"), "field")
params.Add(jsonutils.NewString("system"), "scope")
params.Add(jsonutils.JSONTrue, "usable")
params.Add(jsonutils.JSONTrue, "show_emulated")
cap, err := modules.Hosts.Get(s2, "distinct-field", params)
if err != nil {
log.Errorf("modules.Capabilities.List fail %s", err)
log.Errorf("modules.Servers.Get distinct-field fail %s", err)
} else {
hypervisors, _ := cap.Data[0].Get("hypervisors")
data.Add(hypervisors, "hypervisors")
hostTypes, _ := jsonutils.GetStringArray(cap, "host_type")
hypervisors := make([]string, len(hostTypes))
for i, hostType := range hostTypes {
hypervisors[i] = compute.HOSTTYPE_HYPERVISOR[hostType]
}
data.Add(jsonutils.NewStringArray(hypervisors), "hypervisors")
}
data.Add(menus, "menus")

View File

@@ -0,0 +1,19 @@
// Copyright 2019 Yunion
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package handler
import (
_ "yunion.io/x/onecloud/pkg/mcclient/modules/cloudnet"
)

View File

@@ -28,6 +28,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/utils"
"yunion.io/x/onecloud/pkg/apigateway/options"
"yunion.io/x/onecloud/pkg/appctx"
@@ -37,6 +38,7 @@ import (
"yunion.io/x/onecloud/pkg/mcclient/auth"
"yunion.io/x/onecloud/pkg/mcclient/modulebase"
"yunion.io/x/onecloud/pkg/mcclient/modules"
"yunion.io/x/onecloud/pkg/util/httputils"
)
const (
@@ -171,19 +173,23 @@ func (mh *MiscHandler) DoBatchHostRegister(ctx context.Context, w http.ResponseW
}
paramKeys := []string{}
for _, title := range rows[0] {
i1 := -1
i2 := -1
for i, title := range rows[0] {
switch title {
case HOST_MAC:
paramKeys = append(paramKeys, "access_mac")
case HOST_NAME:
paramKeys = append(paramKeys, "name")
case HOST_IPMI_ADDR, HOST_IPMI_ADDR_OPTIONAL:
i1 = i
paramKeys = append(paramKeys, "ipmi_ip_addr")
case HOST_IPMI_USERNAME, HOST_IPMI_USERNAME_OPTIONAL:
paramKeys = append(paramKeys, "ipmi_username")
case HOST_IPMI_PASSWORD, HOST_IPMI_PASSWORD_OPTIONAL:
paramKeys = append(paramKeys, "ipmi_password")
case HOST_MNG_IP_ADDR, HOST_MNG_IP_ADDR_OPTIONAL:
i2 = i
paramKeys = append(paramKeys, "access_ip")
default:
e := httperrors.NewInternalServerError("empty file content")
@@ -199,8 +205,33 @@ func (mh *MiscHandler) DoBatchHostRegister(ctx context.Context, w http.ResponseW
return
}
ips := []string{}
hosts := bytes.Buffer{}
for _, row := range rows[1:] {
var e *httputils.JSONClientError
if i1 >= 0 && len(row[i1]) > 0 {
i1Ip := fmt.Sprintf("%d-%s", i1, row[i1])
if utils.IsInStringArray(i1Ip, ips) {
e = httperrors.NewDuplicateIdError("ip", row[i1])
} else {
ips = append(ips, i1Ip)
}
}
if i2 >= 0 && len(row[i2]) > 0 {
i2Ip := fmt.Sprintf("%d-%s", i2, row[i2])
if utils.IsInStringArray(i2Ip, ips) {
e = httperrors.NewDuplicateIdError("ip", row[i2])
} else {
ips = append(ips, i2Ip)
}
}
if e != nil {
httperrors.JsonClientError(w, e)
return
}
hosts.WriteString(strings.Join(row, ",") + "\n")
}

View File

@@ -606,28 +606,45 @@ func (f *ResourceHandlers) patchJointHandler(ctx context.Context, w http.Respons
}
}
// batch update Joint
// * batch update Joint
// * put specific
// /<resname>/<resid>/<resname2>
// /<resname>/<resid>/<spec>
func (f *ResourceHandlers) batchUpdateJointHandler(ctx context.Context, w http.ResponseWriter, r *http.Request) {
req := newRequest(ctx, w, r).WithMod1().WithMod2()
req := newRequest(ctx, w, r).WithMod1()
if err := req.Error(); err != nil {
httperrors.GeneralServerError(w, err)
return
}
session := req.Session()
module := req.Mod1()
module2 := req.Mod2()
body := req.Body()
query := req.Query()
idlist := fetchIdList(query, w)
if idlist == nil {
if idlist, _ := query.GetArray("id"); len(idlist) == 0 {
// do put specific
spec := req.ResName2()
obj, e := module.PutSpecific(session, req.ResID(), spec, query, body)
if e != nil {
httperrors.GeneralServerError(w, e)
} else {
appsrv.SendJSON(w, obj)
}
return
}
req = req.WithMod2()
if err := req.Error(); err != nil {
httperrors.GeneralServerError(w, err)
return
}
module2 := req.Mod2()
jmod, e := modulebase.GetJointModule2(session, module, module2)
if e != nil { // update joint
httperrors.GeneralServerError(w, e)
return
}
idlist := fetchIdList(query, w)
ret := jmod.BatchUpdate(session, req.ResID(), idlist, query, body)
w.WriteHeader(207)
appsrv.SendJSON(w, modulebase.SubmitResults2JSON(ret))

View File

@@ -56,6 +56,7 @@ const (
CITY_NAN_JING = "Nanjing" //南京
CITY_FO_SHAN = "Foshan" //佛山
CITY_QUAN_ZHOU = "Quanzhou" //泉州
CITY_NEI_MENG_GU = "Neimenggu" //内蒙古
// 日本
CITY_TOKYO = "Tokyo" //东京
@@ -111,6 +112,7 @@ const (
CITY_US_GOV_WEST = "us-gov-west" //???
CITY_SOUTH_CAROLINA = "South Carolina" //南卡罗来纳州
CITY_SALT_LAKE_CITY = "Salt Lake City" //盐湖城
CITY_LAS_VEGAS = "Las Vegas" //拉斯维加斯
// 英国
CITY_LONDON = "London" //伦敦
@@ -149,6 +151,12 @@ const (
// 巴西
CITY_SAO_PAULO = "Sao Paulo" //圣保罗
// 智利
CITY_SANTIAGO = "Santiago" // 圣地亚哥
// 墨西哥
CITY_MEXICO = "Mexico" // 墨西哥
// 荷兰
CITY_HOLLAND = "Holland" //荷兰
@@ -194,4 +202,6 @@ const (
COUNTRY_CODE_VN = "VN" //越南
COUNTRY_CODE_CH = "CH" //瑞士
COUNTRY_CODE_NO = "NO" //挪威
COUNTRY_CODE_MX = "MX" //墨西哥
COUNTRY_CODE_CL = "CL" //智利
)

View File

@@ -62,3 +62,7 @@ func (ra *SRoleAssignment) GetRoles() []string {
func (ra *SRoleAssignment) GetLoginIp() string {
return ""
}
func (ra *SRoleAssignment) GetTokenString() string {
return "faketoken"
}

View File

@@ -144,6 +144,10 @@ var (
"etcd_cacert",
"etcd_cert",
"etcd_key",
"bootstrap_admin_user_password",
"reset_admin_user_password",
"fernet_key_repository",
},
}
)

View File

@@ -25,10 +25,12 @@ type Ring struct {
}
func NewRing(size int) *Ring {
r := Ring{buffer: make([]interface{}, size+1),
r := Ring{
buffer: make([]interface{}, size+1),
header: 0,
tail: 0,
lock: &sync.Mutex{}}
lock: &sync.Mutex{},
}
return &r
}
@@ -58,6 +60,7 @@ func (r *Ring) Pop() interface{} {
return nil
}
ret := r.buffer[r.tail]
r.buffer[r.tail] = nil
r.tail = nextPointer(r.tail, len(r.buffer))
return ret
}

View File

@@ -19,28 +19,33 @@ import (
)
func TestRing(t *testing.T) {
r := NewRing(10)
var v int32 = 10
r.Push(v)
v = 20
r.Push(v)
v = 30
r.Push(v)
v1 := r.Pop().(int32)
if v1 != 10 {
t.Error("Fail")
}
v2 := r.Pop().(int32)
if v2 != 20 {
t.Error("Fail")
}
v3 := r.Pop().(int32)
if v3 != 30 {
t.Error("Fail")
}
v4 := r.Pop()
if v4 != nil {
t.Error("Fail")
var (
r = NewRing(10)
push = func(v int32) {
r.Push(v)
}
pop = func(want int32) {
got := r.Pop().(int32)
if got != want {
t.Fatalf("got %d, want %d", got, want)
}
for i := r.header; i != r.tail; i = nextPointer(i, len(r.buffer)) {
if r.buffer[i] != nil {
t.Fatalf("head %d, tail %d, index %d not nil",
r.header, r.tail, i)
}
}
}
)
push(10)
push(20)
push(30)
pop(10)
pop(20)
pop(30)
if v := r.Pop(); v != nil {
t.Fatalf("want nil, got %#v", v)
}
}

View File

@@ -83,9 +83,6 @@ func (worker *SWorker) run() {
task := req.(*sWorkerTask)
if task.worker != nil {
task.worker <- worker
// worker channel is buffered
// close the worker channel
close(task.worker)
}
execCallback(task)
} else {

View File

@@ -189,10 +189,11 @@ func (job *SLogFetchJob) Do(ctx context.Context, now time.Time) error {
if err != nil {
return errors.Wrap(err, "fetchLogs api.EVENT_TYPE_SYSTEM")
}
err = fetchLogs(job.baremetal, ctx, redfish.EVENT_TYPE_MANAGER)
if err != nil {
return errors.Wrap(err, "fetchLogs api.EVENT_TYPE_MANAGER")
}
// no longer fetch management logs
// err = fetchLogs(job.baremetal, ctx, redfish.EVENT_TYPE_MANAGER)
// if err != nil {
// return errors.Wrap(err, "fetchLogs api.EVENT_TYPE_MANAGER")
// }
job.lastTime = now
return nil
}

View File

@@ -21,6 +21,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/onecloud/pkg/appsrv"
"yunion.io/x/onecloud/pkg/baremetal"
@@ -71,6 +72,7 @@ func initBaremetalsHandler(app *appsrv.Application) {
AddHandler(app, "POST", bmActionPrefix("reset-bmc"), bmObjMiddleware(handleBaremetalResetBMC))
AddHandler(app, "POST", bmActionPrefix("ipmi-probe"), bmObjMiddleware(handleBaremetalIpmiProbe))
AddHandler(app, "POST", bmActionPrefix("cdrom"), bmObjMiddleware(handleBaremetalCdromTask))
AddHandler(app, "POST", bmActionPrefix("jnlp"), bmObjMiddleware(handleBaremetalJnlpTask))
// server actions handler
AddHandler(app, "POST", srvActionPrefix("create"), srvClassMiddleware(handleServerCreate))
@@ -160,6 +162,17 @@ func handleBaremetalCdromTask(ctx *Context, bm *baremetal.SBaremetalInstance) {
ctx.ResponseOk()
}
func handleBaremetalJnlpTask(ctx *Context, bm *baremetal.SBaremetalInstance) {
jnlp, err := bm.GetConsoleJNLP(ctx)
if err != nil {
ctx.ResponseError(errors.Wrap(err, "GetConsoleJNLP"))
return
}
result := jsonutils.NewDict()
result.Add(jsonutils.NewString(jnlp), "jnlp")
ctx.ResponseJson(result)
}
func handleServerCreate(ctx *Context, bm *baremetal.SBaremetalInstance) {
err := bm.StartServerCreateTask(ctx.UserCred(), ctx.TaskId(), ctx.Data())
if err != nil {

View File

@@ -64,6 +64,7 @@ import (
"yunion.io/x/onecloud/pkg/util/influxdb"
"yunion.io/x/onecloud/pkg/util/procutils"
"yunion.io/x/onecloud/pkg/util/redfish"
"yunion.io/x/onecloud/pkg/util/redfish/bmconsole"
"yunion.io/x/onecloud/pkg/util/ssh"
"yunion.io/x/onecloud/pkg/util/sysutils"
)
@@ -1232,7 +1233,12 @@ func (b *SBaremetalInstance) enableWire(mac net.HardwareAddr, ipAddr string, nic
func (b *SBaremetalInstance) GetIPMIConfig() *types.SIPMIInfo {
conf := b.GetRawIPMIConfig()
if conf == nil || conf.Password == "" {
if conf == nil {
log.Debugf("GetIPMIConfig conf is nil")
return nil
}
if conf.Password == "" {
log.Debugf("GetIPMIConfig password is nil")
return nil
}
if conf.Username == "" {
@@ -1251,6 +1257,7 @@ func (b *SBaremetalInstance) GetIPMIConfig() *types.SIPMIInfo {
}
conf.Password = utils.Unquote(conf.Password) // XXX: remove quotes!!!
if conf.IpAddr == "" {
log.Debugf("GetIPMIConfig ipaddr s nil")
return nil
}
return conf
@@ -1333,6 +1340,7 @@ func (b *SBaremetalInstance) SetExistingIPMIIPAddr(ipAddr string) {
func (b *SBaremetalInstance) GetIPMITool() *ipmitool.LanPlusIPMI {
conf := b.GetIPMIConfig()
if conf == nil {
log.Debugf("GetIPMIConfig is nil")
return nil
}
return ipmitool.NewLanPlusIPMI(conf.IpAddr, conf.Username, conf.Password)
@@ -1629,6 +1637,10 @@ func (b *SBaremetalInstance) DelayedSyncIPMIInfo(data jsonutils.JSONObject) (jso
}
func (b *SBaremetalInstance) DelayedSyncDesc(data jsonutils.JSONObject) (jsonutils.JSONObject, error) {
if data == nil {
session := b.manager.GetClientSession()
data, _ = b.manager.fetchBaremetal(session, b.GetId())
}
err := b.SaveDesc(data)
return nil, err
}
@@ -1921,6 +1933,25 @@ func (b *SBaremetalInstance) fetchPowerThermalMetrics(ctx context.Context) ([]in
return powerMetrics, thermalMetrics, nil
}
func (b *SBaremetalInstance) GetConsoleJNLP(ctx context.Context) (string, error) {
cli := b.GetRedfishCli(ctx)
if cli != nil {
return cli.GetConsoleJNLP(ctx)
}
conf := b.GetIPMIConfig()
bmc := bmconsole.NewBMCConsole(conf.IpAddr, conf.Username, conf.Password, false)
manufacture := b.GetManufacture()
switch strings.ToLower(manufacture) {
case "hp", "hpe":
return bmc.GetIloConsoleJNLP(ctx)
case "dell", "dell inc.":
return bmc.GetIdracConsoleJNLP(ctx, "", "")
case "supermicro":
return bmc.GetSupermicroConsoleJNLP(ctx)
}
return "", httperrors.NewNotImplementedError("Unsupported manufacture %s", manufacture)
}
func (b *SBaremetalInstance) getTags() []influxdb.SKeyValue {
tags := []influxdb.SKeyValue{
{

View File

@@ -43,7 +43,7 @@ func InspurProfile() IPMIProfile {
func LenovoProfile() IPMIProfile {
return IPMIProfile{
LanChannel: []int{8},
LanChannel: []int{1, 8},
RootName: "root",
RootId: 2,
}
@@ -51,7 +51,7 @@ func LenovoProfile() IPMIProfile {
func HpProfile() IPMIProfile {
return IPMIProfile{
LanChannel: []int{2},
LanChannel: []int{1, 2},
RootName: "root",
RootId: 1,
}

View File

@@ -64,6 +64,7 @@ func (s *BaremetalService) StartService() {
fsdriver.Init(nil)
app := app_common.InitApp(&o.Options.BaseOptions, false)
handler.InitHandlers(app)
s.startAgent(app)

View File

@@ -306,7 +306,13 @@ func (self *SBaremetalTaskBase) EnsurePowerUp() error {
if err != nil {
return errors.Wrapf(err, "Get power status")
}
maxTries := 10
count := 0
for status == "" || status == types.POWER_STATUS_OFF {
if count > maxTries {
break
}
log.Infof("Try power on %d times, pxe boot %v", count+1, self.PxeBoot)
if status == types.POWER_STATUS_OFF {
if self.PxeBoot {
err = self.Baremetal.DoPXEBoot()
@@ -314,7 +320,7 @@ func (self *SBaremetalTaskBase) EnsurePowerUp() error {
err = self.Baremetal.DoRedfishPowerOn()
}
if err != nil {
return errors.Wrapf(err, "Do boot power on")
log.Warningf("Do boot power on error: %v", err)
}
}
status, err = self.Baremetal.GetPowerStatus()
@@ -328,6 +334,7 @@ func (self *SBaremetalTaskBase) EnsurePowerUp() error {
return err
}
}
count++
}
if status != types.POWER_STATUS_ON {
return fmt.Errorf("Baremetal invalid restart status: %s", status)

View File

@@ -108,7 +108,9 @@ func (task *sBaremetalPrepareTask) prepareBaremetalInfo(cli *ssh.Client) (*barem
if len(raidDiskInfo) > 0 {
raidDrivers := []string{}
for _, drv := range raidDiskInfo {
raidDrivers = append(raidDrivers, drv.Driver)
if !utils.IsInStringArray(drv.Driver, raidDrivers) {
raidDrivers = append(raidDrivers, drv.Driver)
}
}
storageDriver = strings.Join(raidDrivers, ",")
} else {

View File

@@ -249,11 +249,17 @@ func (adapter *HPSARaidAdaptor) buildRaid(level string, devs []*baremetal.Bareme
return fmt.Errorf("getLastArray: %v", err)
}
cmds := []string{}
for _, sz := range conf.Size[1:] {
restSize := conf.Size[1:]
for idx, sz := range restSize {
isLast := idx == len(restSize)-1
sizeStr := fmt.Sprintf("size=%d", sz)
if isLast {
sizeStr = "size=max"
}
args = []string{"controller", fmt.Sprintf("slot=%d", adapter.index),
"array", array, "create", "type=ld",
fmt.Sprintf("raid=%s", level),
fmt.Sprintf("size=%d", sz),
sizeStr,
}
args = append(args, params...)
cmds = append(cmds, GetCommand(args...))

View File

@@ -83,8 +83,9 @@ func InitAuth(options *common_options.CommonOptions, authComplete auth.AuthCompl
func InitBaseAuth(options *common_options.BaseOptions) {
if options.EnableRbac {
policy.EnableGlobalRbac(time.Duration(options.RbacPolicySyncPeriodSeconds)*time.Second,
time.Duration(options.RbacPolicySyncFailedRetrySeconds)*time.Second,
policy.EnableGlobalRbac(
time.Second*time.Duration(options.RbacPolicySyncPeriodSeconds),
time.Second*time.Duration(options.RbacPolicySyncFailedRetrySeconds),
options.RbacDebug,
)
}

View File

@@ -653,7 +653,7 @@ func calculateListResult(data []jsonutils.JSONObject, total, limit, offset int64
}
}
// do limit
if limit > 0 && total > limit {
if limit > 0 && total-offset > limit {
data = data[:limit]
}
}
@@ -1120,6 +1120,12 @@ func (dispatcher *DBModelDispatcher) Create(ctx context.Context, query jsonutils
model, err := DoCreate(dispatcher.modelManager, ctx, userCred, query, data, ownerId)
if err != nil {
// log.Errorf("fail to doCreateItem %s", err)
if CancelPendingUsagesInContext != nil {
err := CancelPendingUsagesInContext(ctx, userCred)
if err != nil {
log.Errorf("CancelPendingUsagesInContext fail %s", err)
}
}
failErr := manager.OnCreateFailed(ctx, userCred, ownerId, query, data)
if failErr != nil {
log.Errorf("manager.OnCreateFailed %s", failErr)
@@ -1308,6 +1314,19 @@ func managerPerformCheckCreateData(
return nil, httperrors.NewForbiddenError("not allow to perform %s", action)
}
if InitPendingUsagesInContext != nil {
ctx = InitPendingUsagesInContext(ctx)
defer func() {
if CancelPendingUsagesInContext != nil {
err := CancelPendingUsagesInContext(ctx, userCred)
if err != nil {
log.Errorf("CancelPendingUsagesInContext fail %s", err)
}
}
}()
}
return ValidateCreateData(manager, ctx, userCred, ownerId, query, bodyDict)
}

View File

@@ -22,7 +22,6 @@ import (
"time"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
@@ -391,12 +390,6 @@ func (manager *SModelBaseManager) BatchCreateValidateCreateData(ctx context.Cont
}
func (manager *SModelBaseManager) OnCreateFailed(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data jsonutils.JSONObject) error {
if CancelPendingUsagesInContext != nil {
err := CancelPendingUsagesInContext(ctx, userCred)
if err != nil {
return errors.Wrap(err, "CancelPendingUsagesInContext")
}
}
return nil
}

View File

@@ -20,6 +20,7 @@ import (
"fmt"
"net/http"
"reflect"
"sort"
"strings"
"yunion.io/x/jsonutils"
@@ -435,7 +436,7 @@ func (manager *SQuotaBaseManager) listDomainQuotaHandler(ctx context.Context, w
httperrors.GeneralServerError(w, err)
return
}
manager.sendQuotaList(w, quotaList)
manager.sendQuotaList(w, sortQuotaByUsage(quotaList))
}
func (manager *SQuotaBaseManager) sendQuotaList(w http.ResponseWriter, quotaList []jsonutils.JSONObject) {
@@ -478,7 +479,7 @@ func (manager *SQuotaBaseManager) listProjectQuotaHandler(ctx context.Context, w
httperrors.GeneralServerError(w, err)
return
}
manager.sendQuotaList(w, quotaList)
manager.sendQuotaList(w, sortQuotaByUsage(quotaList))
}
func (manager *SQuotaBaseManager) listQuotas(ctx context.Context, userCred mcclient.TokenCredential, targetDomainId string, targetProjectId string, domainOnly bool, primaryOnly bool, refresh bool) ([]jsonutils.JSONObject, error) {
@@ -566,3 +567,33 @@ func (manager *SQuotaBaseManager) listQuotas(ctx context.Context, userCred mccli
}
return ret, nil
}
type tQuotaResultList []jsonutils.JSONObject
func (a tQuotaResultList) Len() int { return len(a) }
func (a tQuotaResultList) Swap(i, j int) { a[i], a[j] = a[j], a[i] }
func (a tQuotaResultList) Less(i, j int) bool { return usageRateOfQuota(a[i]) > usageRateOfQuota(a[j]) }
func usageRateOfQuota(quota jsonutils.JSONObject) float32 {
maxRate := float32(0)
quotaMap, _ := quota.GetMap()
for k, v := range quotaMap {
usageK := fmt.Sprintf("usage.%s", k)
if usageV, ok := quotaMap[usageK]; ok {
intV, _ := v.Int()
if intV > 0 {
intUsageV, _ := usageV.Int()
rate := float32(intUsageV) / float32(intV)
if maxRate < rate {
maxRate = rate
}
}
}
}
return maxRate
}
func sortQuotaByUsage(quotaList []jsonutils.JSONObject) []jsonutils.JSONObject {
sort.Sort(tQuotaResultList(quotaList))
return quotaList
}

View File

@@ -70,7 +70,7 @@ func isObjectRbacAllowed(model IModel, userCred mcclient.TokenCredential, action
if !requireScope.HigherThan(scope) {
return nil
}
return httperrors.NewForbiddenError(fmt.Sprintf("not enough privillege(require:%s,allow:%s)", requireScope, scope))
return httperrors.NewForbiddenError(fmt.Sprintf("not enough privilege(require:%s,allow:%s)", requireScope, scope))
}
func isJointObjectRbacAllowed(item IJointModel, userCred mcclient.TokenCredential, action string, extra ...string) error {

View File

@@ -66,8 +66,8 @@ func RegistUserCredCacheUpdater() {
auth.RegisterAuthHook(onAuthCompleteUpdateCache)
}
func onAuthCompleteUpdateCache(userCred mcclient.TokenCredential) {
TenantCacheManager.updateTenantCache(userCred)
func onAuthCompleteUpdateCache(ctx context.Context, userCred mcclient.TokenCredential) {
TenantCacheManager.updateTenantCache(ctx, userCred)
UserCacheManager.updateUserCache(userCred)
}
@@ -91,8 +91,8 @@ func (manager *STenantCacheManager) InitializeData() error {
return nil
}
func (manager *STenantCacheManager) updateTenantCache(userCred mcclient.TokenCredential) {
manager.Save(context.Background(), userCred.GetProjectId(), userCred.GetProjectName(),
func (manager *STenantCacheManager) updateTenantCache(ctx context.Context, userCred mcclient.TokenCredential) {
manager.Save(ctx, userCred.GetProjectId(), userCred.GetProjectName(),
userCred.GetProjectDomainId(), userCred.GetProjectDomain())
}
@@ -348,14 +348,14 @@ func (manager *STenantCacheManager) findFirstProjectOfDomain(domainId string) (*
return &tenant, nil
}
func (manager *STenantCacheManager) fetchDomainTenantsFromKeystone(domainId string) error {
func (manager *STenantCacheManager) fetchDomainTenantsFromKeystone(ctx context.Context, domainId string) error {
if len(domainId) == 0 {
log.Debugf("fetch empty domain!!!!")
debug.PrintStack()
return fmt.Errorf("Empty domainId")
}
s := auth.GetAdminSession(context.Background(), consts.GetRegion(), "v1")
s := auth.GetAdminSession(ctx, consts.GetRegion(), "v1")
params := jsonutils.Marshal(map[string]string{"domain_id": domainId})
tenants, err := modules.Projects.List(s, params)
if err != nil {
@@ -366,7 +366,7 @@ func (manager *STenantCacheManager) fetchDomainTenantsFromKeystone(domainId stri
tenantName, _ := tenant.GetString("name")
domainId, _ := tenant.GetString("domain_id")
domainName, _ := tenant.GetString("project_domain")
_, err = manager.Save(context.Background(), tenantId, tenantName, domainId, domainName)
_, err = manager.Save(ctx, tenantId, tenantName, domainId, domainName)
if err != nil {
return err
}
@@ -374,11 +374,11 @@ func (manager *STenantCacheManager) fetchDomainTenantsFromKeystone(domainId stri
return nil
}
func (manager *STenantCacheManager) FindFirstProjectOfDomain(domainId string) (*STenant, error) {
func (manager *STenantCacheManager) FindFirstProjectOfDomain(ctx context.Context, domainId string) (*STenant, error) {
tenant, err := manager.findFirstProjectOfDomain(domainId)
if err != nil {
if err == sql.ErrNoRows {
err = manager.fetchDomainTenantsFromKeystone(domainId)
err = manager.fetchDomainTenantsFromKeystone(ctx, domainId)
if err != nil {
return nil, errors.Wrap(err, "fetchDomainTenantsFromKeystone")
}

View File

@@ -20,6 +20,7 @@ import (
"sort"
"strings"
"sync"
"sync/atomic"
"time"
"yunion.io/x/jsonutils"
@@ -80,35 +81,42 @@ type SPolicyManager struct {
lock *sync.Mutex
}
type sPolicyData struct {
Type string `json:"type"`
Enabled bool `json:"enabled"`
DomainId string `json:"domain_id"`
IsPublic bool `json:"is_public"`
Policy jsonutils.JSONObject `json:"policy"`
}
func parseJsonPolicy(obj jsonutils.JSONObject) (string, *rbacutils.SRbacPolicy, error) {
typeStr, err := obj.GetString("type")
pData := sPolicyData{}
err := obj.Unmarshal(&pData)
if err != nil {
return "", nil, errors.Wrap(err, "missing type")
return "", nil, errors.Wrap(err, "Unmarshal")
}
domainId, err := obj.GetString("domain_id")
if err != nil {
return "", nil, errors.Wrap(err, "missing domain_id")
if !pData.Enabled {
return "", nil, errors.Wrap(httperrors.ErrInputParameter, "not enabled")
}
if len(pData.Type) == 0 {
return "", nil, errors.Wrap(httperrors.ErrInputParameter, "missing type")
}
isPublic := jsonutils.QueryBoolean(obj, "is_public", false)
blob, err := obj.Get("policy")
if err != nil {
log.Errorf("get blob error %s", err)
return "", nil, errors.Wrap(err, "json.Get")
if pData.Policy == nil {
return "", nil, errors.Wrap(httperrors.ErrInputParameter, "missing policy")
}
policy := rbacutils.SRbacPolicy{}
err = policy.Decode(blob)
err = policy.Decode(pData.Policy)
if err != nil {
log.Errorf("policy decode error %s", err)
return "", nil, errors.Wrap(err, "policy.Decode")
}
policy.DomainId = domainId
policy.IsPublic = isPublic
policy.DomainId = pData.DomainId
policy.IsPublic = pData.IsPublic
return typeStr, &policy, nil
return pData.Type, &policy, nil
}
func remotePolicyFetcher() (map[rbacutils.TRbacScope]map[string]*rbacutils.SRbacPolicy, error) {
@@ -121,7 +129,7 @@ func remotePolicyFetcher() (map[rbacutils.TRbacScope]map[string]*rbacutils.SRbac
params := jsonutils.NewDict()
params.Add(jsonutils.NewInt(2048), "limit")
params.Add(jsonutils.NewInt(int64(offset)), "offset")
params.Add(jsonutils.JSONTrue, "admin")
params.Add(jsonutils.NewString("system"), "scope")
params.Add(jsonutils.JSONTrue, "enabled")
result, err := modules.Policies.List(s, params)
if err != nil {
@@ -165,16 +173,38 @@ func (manager *SPolicyManager) start(refreshInterval time.Duration, retryInterva
policiesMap[policy.Scope] = policies
}
manager.defaultPolicies = policiesMap
log.Debugf("%#v", manager.defaultPolicies)
// log.Debugf("%#v", manager.defaultPolicies)
}
manager.cache = hashcache.NewCache(2048, manager.refreshInterval/2)
manager.SyncOnce()
manager.syncByInterval()
}
func (manager *SPolicyManager) syncByInterval() {
syncWorkerManager.Run(manager.syncByInterval_, nil, nil)
}
func (manager *SPolicyManager) syncByInterval_() {
err := manager.doSync()
var interval time.Duration
if err != nil {
interval = manager.failedRetryInterval
} else {
interval = manager.refreshInterval
}
time.AfterFunc(interval, manager.syncByInterval)
}
var syncOnce int32
func (manager *SPolicyManager) SyncOnce() {
syncWorkerManager.Run(manager.sync, nil, nil)
if atomic.CompareAndSwapInt32(&syncOnce, 0, 1) {
syncWorkerManager.Run(func() {
atomic.StoreInt32(&syncOnce, 0)
manager.doSync()
}, nil, nil)
}
}
func (manager *SPolicyManager) doSync() error {
@@ -202,17 +232,6 @@ func (manager *SPolicyManager) doSync() error {
return nil
}
func (manager *SPolicyManager) sync() {
err := manager.doSync()
var interval time.Duration
if err != nil {
interval = manager.failedRetryInterval
} else {
interval = manager.refreshInterval
}
time.AfterFunc(interval, manager.SyncOnce)
}
func queryKey(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) string {
queryKeys := []string{string(scope)}
queryKeys = append(queryKeys, userCred.GetProjectId(), userCred.GetDomainId(), userCred.GetUserId())
@@ -315,42 +334,16 @@ func (manager *SPolicyManager) findPolicyByName(scope rbacutils.TRbacScope, name
}
func getMatchedPolicyNames(policies map[string]*rbacutils.SRbacPolicy, userCred rbacutils.IRbacIdentity) []string {
matchNames := make([]string, 0)
maxMatchWeight := 0
for k := range policies {
isMatched, matchWeight := policies[k].Match(userCred)
if !isMatched || matchWeight < maxMatchWeight {
continue
}
if maxMatchWeight < matchWeight {
maxMatchWeight = matchWeight
matchNames = matchNames[:0]
}
matchNames = append(matchNames, k)
}
_, matchNames := rbacutils.GetMatchedPolicies(policies, userCred)
return matchNames
}
func getMatchedPolicyRules(policies map[string]*rbacutils.SRbacPolicy, userCred rbacutils.IRbacIdentity, service string, resource string, action string, extra ...string) ([]rbacutils.SRbacRule, bool) {
matchRules := make([]rbacutils.SRbacRule, 0)
findMatchPolicy := false
maxMatchWeight := 0
for k := range policies {
isMatched, matchWeight := policies[k].Match(userCred)
if !isMatched || matchWeight < maxMatchWeight {
continue
}
if maxMatchWeight < matchWeight {
maxMatchWeight = matchWeight
matchRules = matchRules[:0]
}
findMatchPolicy = true
rule := policies[k].GetMatchRule(service, resource, action, extra...)
if rule != nil {
matchRules = append(matchRules, *rule)
}
matchPolicies, _ := rbacutils.GetMatchedPolicies(policies, userCred)
if len(matchPolicies) == 0 {
return nil, false
}
return matchRules, findMatchPolicy
return matchPolicies.GetMatchRules(service, resource, action, extra...), true
}
func (manager *SPolicyManager) allowWithoutCache(scope rbacutils.TRbacScope, userCred mcclient.TokenCredential, service string, resource string, action string, extra ...string) rbacutils.TRbacResult {
@@ -406,8 +399,15 @@ func (manager *SPolicyManager) allowWithoutCache(scope rbacutils.TRbacScope, use
var result rbacutils.TRbacResult
if len(matchRules) > 0 {
rule := rbacutils.GetMatchRule(matchRules, service, resource, action, extra...)
result = rule.Result
result = rbacutils.Deny
for _, rule := range matchRules {
if rule.Result == rbacutils.Allow {
result = rbacutils.Allow
break
}
}
// rule := rbacutils.GetMatchRule(matchRules, service, resource, action, extra...)
// result = rule.Result
} else if findMatchPolicy {
// if find matched policy, but no rule matching, allow anyway
result = rbacutils.Allow
@@ -520,7 +520,7 @@ func (manager *SPolicyManager) IsScopeCapable(userCred mcclient.TokenCredential,
return false
}
func (manager *SPolicyManager) MatchedPolicies(scope rbacutils.TRbacScope, userCred rbacutils.IRbacIdentity) []string {
func (manager *SPolicyManager) MatchedPolicyNames(scope rbacutils.TRbacScope, userCred rbacutils.IRbacIdentity) []string {
ret := make([]string, 0)
policies, ok := manager.policies[scope]
if !ok {
@@ -544,13 +544,28 @@ func (manager *SPolicyManager) AllPolicies() map[string][]string {
}
func (manager *SPolicyManager) RoleMatchPolicies(roleName string) []string {
ident := rbacutils.NewRbacIdentity("", "", []string{roleName})
ret := make([]string, 0)
for _, policies := range manager.policies {
for name, policy := range policies {
if policy.MatchRole(roleName) {
if matched, _ := policy.Match(ident); matched {
ret = append(ret, name)
}
}
}
return ret
}
func (manager *SPolicyManager) GetMatchedPolicySet(userCred rbacutils.IRbacIdentity) (rbacutils.TRbacScope, rbacutils.TPolicySet) {
for _, scope := range []rbacutils.TRbacScope{
rbacutils.ScopeSystem,
rbacutils.ScopeDomain,
rbacutils.ScopeProject,
} {
macthed, _ := rbacutils.GetMatchedPolicies(manager.policies[scope], userCred)
if len(macthed) > 0 {
return scope, macthed
}
}
return rbacutils.ScopeNone, nil
}

View File

@@ -66,7 +66,9 @@ var (
meterDomainResources = []string{}
meterUserResources = []string{}
k8sSystemResources = []string{}
k8sSystemResources = []string{
"repos",
}
k8sDomainResources = []string{}
k8sUserResources = []string{}

View File

@@ -32,33 +32,66 @@ const (
)
type SCloudaccountCredential struct {
ProjectName string //OpenStack
DomainName string //OpenStack
Username string //OpenStack Esxi ZStack
Password string //OpenStack Esxi ZStack
AuthUrl string //OpenStack ZStack
// 账号所在的项目 (openstack)
ProjectName string `json:"project_name"`
AccessKeyId string //Huawei Aliyun Ucloud Aws
AccessKeySecret string //Huawei Aliyun Ucloud Aws
Environment string //Huawei Azure Aws
// 账号所在的域 (openstack)
// default: Default
DomainName string `json:"domain_name"`
DirectoryId string //Azure
ClientId string //Azure
ClientSecret string //Azure
// 用户名 (openstack, zstack, esxi)
Username string `json:"username"`
Host string //Esxi
Port int //Esxi
// 密码 (openstack, zstack, esxi)
Password string `json:"password"`
Endpoint string
// 认证地址 (openstack,zstack)
AuthUrl string `json:"auto_url"`
AppId string //Qcloud
SecretId string //Qcloud
SecretKey string //Qcloud
// 秘钥id (Aliyun, Aws, huawei, ucloud, ctyun, zstack, s3)
AccessKeyId string `json:"access_key_id"`
ClientEmail string //Google
ProjectId string //Google
PrivateKeyId string //Google
PrivateKey string //Google
// 秘钥key (Aliyun, Aws, huawei, ucloud, ctyun, zstack, s3)
AccessKeySecret string `json:"access_key_secret"`
// 环境 (Azure, Aws, huawei, ctyun)
Environment string `json:"environment"`
// 目录ID (Azure)
DirectoryId string `json:"directory_id"`
// 客户端ID (Azure)
ClientId string `json:"client_id"`
// 客户端秘钥 (Azure)
ClientSecret string `json:"client_secret"`
// 主机IP (esxi)
Host string `json:"host"`
// 主机端口 (esxi)
Port int `json:"port"`
// 端点 (s3)
Endpoint string `json:"endpoint"`
// app id (Qcloud)
AppId string `json:"app_id"`
//秘钥ID (Qcloud)
SecretId string `json:"secret_id"`
//秘钥key (Qcloud)
SecretKey string `json:"secret_key"`
// Google服务账号email (gcp)
GCPClientEmail string `json:"gcp_client_email"`
// Google服务账号project id (gcp)
GCPProjectId string `json:"gcp_project_id"`
// Google服务账号秘钥id (gcp)
GCPPrivateKeyId string `json:"gcp_private_key_id"`
// Google服务账号秘钥 (gcp)
GCPPrivateKey string `json:"gcp_private_key"`
}
type SCloudaccount struct {
@@ -159,7 +192,7 @@ func GetProviderFactory(provider string) (ICloudProviderFactory, error) {
if ok {
return factory, nil
}
log.Errorf("Provider %s not registerd", provider)
log.Errorf("Provider %s not registered", provider)
return nil, fmt.Errorf("No such provider %s", provider)
}

View File

@@ -270,6 +270,7 @@ func GetIBucketStats(bucket ICloudBucket) (SBucketStats, error) {
if objs.IsTruncated {
return stats, errors.Wrap(httperrors.ErrTooLarge, "too many objects")
}
stats.ObjectCount = 0
for _, obj := range objs.Objects {
stats.SizeBytes += obj.GetSizeBytes()
stats.ObjectCount += 1

View File

@@ -20,7 +20,6 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/tristate"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/billing"
@@ -336,10 +335,10 @@ type ICloudSecurityGroup interface {
ICloudResource
GetDescription() string
GetRules() ([]secrules.SecurityRule, error)
GetRules() ([]SecurityRule, error)
GetVpcId() string
SyncRules(rules []secrules.SecurityRule) error
SyncRules(common, inAdds, outAdds, inDels, outDels []SecurityRule) error
Delete() error
}

View File

@@ -14,7 +14,15 @@
package cloudprovider
import "yunion.io/x/pkg/util/secrules"
import (
"sort"
"strings"
"yunion.io/x/log"
"yunion.io/x/pkg/util/secrules"
)
const DEFAULT_CLOUD_RULE_ID = "default_cloud_rule_id"
type SecurityGroupCreateInput struct {
Name string
@@ -22,3 +30,268 @@ type SecurityGroupCreateInput struct {
VpcId string
Rules []secrules.SecurityRule
}
type SecurityRule struct {
secrules.SecurityRule
Name string
ExternalId string
}
type TPriorityOrder int
var (
PriorityOrderByDesc = TPriorityOrder(1)
PriorityOrderByAsc = TPriorityOrder(-1)
)
func (r SecurityRule) String() string {
return r.SecurityRule.String()
}
type SecurityRuleSet []SecurityRule
func (srs SecurityRuleSet) Len() int {
return len(srs)
}
func (srs SecurityRuleSet) Swap(i, j int) {
srs[i], srs[j] = srs[j], srs[i]
}
func (srs SecurityRuleSet) Less(i, j int) bool {
return srs[i].Priority < srs[j].Priority || (srs[i].Priority == srs[j].Priority && srs[i].String() < srs[j].String())
}
func (srs SecurityRuleSet) AllowList() secrules.SecurityRuleSet {
rules := secrules.SecurityRuleSet{}
for _, r := range srs {
rules = append(rules, r.SecurityRule)
}
return rules.AllowList()
}
func AddDefaultRule(rules []SecurityRule, defaultRule SecurityRule, localRuleStr string, order TPriorityOrder, min, max int, onlyAllowRules bool) []SecurityRule {
if defaultRule.String() == localRuleStr {
return rules
}
defaultRule.ExternalId = DEFAULT_CLOUD_RULE_ID
if order == PriorityOrderByDesc {
defaultRule.Priority = min
} else {
defaultRule.Priority = max
}
defaultRule.Priority -= int(order)
if onlyAllowRules {
defaultRule.Priority = -1
}
return append(rules, defaultRule)
}
func SortSecurityRule(rules SecurityRuleSet, order TPriorityOrder, onlyAllowRules bool) {
if onlyAllowRules {
sort.Sort(rules)
return
}
if order == PriorityOrderByAsc {
sort.Sort(sort.Reverse(rules))
return
}
sort.Sort(rules)
}
func CompareRules(
minPriority, maxPriority int, order TPriorityOrder,
localRules secrules.SecurityRuleSet, remoteRules []SecurityRule,
defaultInRule, defaultOutRule SecurityRule,
onlyAllowRules bool, debug bool,
) (common, inAdds, outAdds, inDels, outDels []SecurityRule) {
localInRules := secrules.SecurityRuleSet{}
localOutRules := secrules.SecurityRuleSet{}
for i := range localRules {
if localRules[i].Direction == secrules.DIR_IN {
localInRules = append(localInRules, localRules[i])
} else {
localOutRules = append(localOutRules, localRules[i])
}
}
inRules := SecurityRuleSet{}
outRules := SecurityRuleSet{}
for i := 0; i < len(remoteRules); i++ {
if remoteRules[i].Direction == secrules.DIR_IN {
inRules = append(inRules, remoteRules[i])
} else {
outRules = append(outRules, remoteRules[i])
}
}
var inCommon, outCommon = inRules, outRules
defaultLocalInRule := *secrules.MustParseSecurityRule("in:deny any")
defaultLocalOutRule := *secrules.MustParseSecurityRule("out:allow any")
inRules = AddDefaultRule(inRules, defaultInRule, defaultLocalInRule.String(), order, minPriority, maxPriority, onlyAllowRules)
outRules = AddDefaultRule(outRules, defaultOutRule, defaultLocalOutRule.String(), order, minPriority, maxPriority, onlyAllowRules)
if defaultLocalInRule.String() != defaultInRule.String() {
localInRules = append(localInRules, defaultLocalInRule)
}
if defaultLocalOutRule.String() != defaultOutRule.String() {
localOutRules = append(localOutRules, defaultLocalOutRule)
}
sort.Sort(localInRules)
sort.Sort(localOutRules)
localInAllowList := localInRules.AllowList()
localOutAllowList := localOutRules.AllowList()
if onlyAllowRules {
localInRules = localInAllowList
localOutRules = localOutAllowList
}
SortSecurityRule(inRules, order, onlyAllowRules)
SortSecurityRule(outRules, order, onlyAllowRules)
inAllowList := inRules.AllowList()
outAllowList := outRules.AllowList()
inEquals, outEquals := inAllowList.Equals(localInAllowList), outAllowList.Equals(localOutAllowList)
if inEquals && outEquals {
return
}
// priority从小到大排列(从默认规则开始对比)
sort.Sort(sort.Reverse(localInRules))
sort.Sort(sort.Reverse(localOutRules))
sort.Sort(sort.Reverse(inRules))
sort.Sort(sort.Reverse(outRules))
startPriority := minPriority - 1
if order == PriorityOrderByAsc {
startPriority = maxPriority + 1
}
var addPriority = func(priority int, order TPriorityOrder, inc int, min, max int, onlyAllowRules bool) int {
if onlyAllowRules {
return 0
}
inc = inc * int(order) //+ int(order)
priority += inc
if priority < min {
return min
}
if priority > max {
return max
}
return priority
}
var getInitPriority = func(init, min, max int) int {
if init < min || init > max {
return (min + max) / 2
}
return init
}
var compare = func(localRules secrules.SecurityRuleSet, remoteRules SecurityRuleSet) (common, add, del []SecurityRule) {
i, j, inc, prePriority := 0, 0, 1, 0
for i < len(localRules) || j < len(remoteRules) {
if i < len(localRules) && j < len(remoteRules) {
ruleStr := remoteRules[j].String()
localRuleStr := localRules[i].String()
if debug {
log.Debugf("compare local priority(%d) %s -> remote name(%s) priority(%d) %s\n", localRules[i].Priority, localRules[i].String(), remoteRules[j].Name, remoteRules[j].Priority, remoteRules[j].String())
}
cmp := strings.Compare(ruleStr, localRuleStr)
if cmp == 0 {
prePriority = remoteRules[j].Priority
if remoteRules[j].ExternalId == DEFAULT_CLOUD_RULE_ID {
remoteRules[j].Priority = addPriority(remoteRules[j].Priority, order, 1, minPriority, maxPriority, onlyAllowRules)
}
common = append(common, remoteRules[j])
i++
j++
} else if cmp < 0 {
if remoteRules[j].ExternalId != DEFAULT_CLOUD_RULE_ID {
del = append(del, remoteRules[j])
}
j++
} else {
initPriority := getInitPriority(prePriority, minPriority, maxPriority)
localRules[i].Priority = addPriority(initPriority, order, inc, minPriority, maxPriority, onlyAllowRules)
add = append(add, SecurityRule{SecurityRule: localRules[i]})
i++
inc++
}
} else if i >= len(localRules) {
if remoteRules[j].ExternalId != DEFAULT_CLOUD_RULE_ID {
del = append(del, remoteRules[j])
}
j++
} else if j >= len(remoteRules) {
initPriority := startPriority
if len(remoteRules) > 0 {
initPriority = remoteRules[len(remoteRules)-1].Priority
}
initPriority = getInitPriority(initPriority, minPriority, maxPriority) // 若是初始添加规则,尽量以中间为节点,避免仅出现天地规则
localRules[i].Priority = addPriority(initPriority, order, inc, minPriority, maxPriority, onlyAllowRules)
add = append(add, SecurityRule{SecurityRule: localRules[i]})
i++
inc++
}
}
return
}
type rulePair struct {
localRules []secrules.SecurityRule
remoteRules []SecurityRule
protocol string
}
var splitRules = func(localRules []secrules.SecurityRule, remoteRules []SecurityRule) []rulePair {
rules := map[string]rulePair{}
for _, r := range localRules {
pair, ok := rules[r.Protocol]
if !ok {
pair = rulePair{localRules: []secrules.SecurityRule{}, remoteRules: []SecurityRule{}, protocol: r.Protocol}
}
pair.localRules = append(pair.localRules, r)
rules[r.Protocol] = pair
}
for _, r := range remoteRules {
pair, ok := rules[r.Protocol]
if !ok {
pair = rulePair{localRules: []secrules.SecurityRule{}, remoteRules: []SecurityRule{}, protocol: r.Protocol}
}
pair.remoteRules = append(pair.remoteRules, r)
rules[r.Protocol] = pair
}
ret := []rulePair{}
for _, r := range rules {
ret = append(ret, r)
}
return ret
}
var compareRules = func(localRules []secrules.SecurityRule, remoteRules []SecurityRule) (common, add, dels []SecurityRule) {
pairs := splitRules(localRules, remoteRules)
for _, r := range pairs {
_common, _add, _dels := compare(r.localRules, r.remoteRules)
common = append(common, _common...)
add = append(add, _add...)
dels = append(dels, _dels...)
}
return
}
if !inEquals {
inCommon, inAdds, inDels = compareRules(localInRules, inRules)
}
if !outEquals {
outCommon, outAdds, outDels = compareRules(localOutRules, outRules)
}
common = append(inCommon, outCommon...)
return
}

View File

@@ -549,7 +549,7 @@ func GetDiskSpecV2(storages []*BaremetalStorage) api.DiskDriverSpec {
if len(driverStorages) == 0 {
continue
}
spec[driver] = getSpec(storages)
spec[driver] = getSpec(driverStorages)
}
return spec
}

View File

@@ -1009,7 +1009,7 @@ func (self *SManagedVirtualizedGuestDriver) RequestAssociateEip(ctx context.Cont
return nil, fmt.Errorf("ManagedVirtualizedGuestDriver.RequestAssociateEip fail to local associate EIP %s", err)
}
eip.SetStatus(userCred, api.EIP_STATUS_READY, "associate")
eip.SetStatus(userCred, api.EIP_STATUS_READY, api.EIP_STATUS_ASSOCIATE)
return nil, nil
})

View File

@@ -661,10 +661,10 @@ func (bucket *SBucket) GetDetailsObjects(
}
ret := jsonutils.NewDict()
ret.Add(retArray, "data")
ret.Add(jsonutils.NewString("key"), "marker_field")
ret.Add(jsonutils.NewString("DESC"), "marker_order")
if len(nextMarker) > 0 {
ret.Add(jsonutils.NewString(nextMarker), "next_marker")
ret.Add(jsonutils.NewString("key"), "marker_field")
ret.Add(jsonutils.NewString("DESC"), "marker_order")
}
return ret, nil
}

View File

@@ -22,6 +22,7 @@ import (
"net/url"
"strconv"
"strings"
"sync"
"time"
"yunion.io/x/jsonutils"
@@ -549,13 +550,13 @@ func (self *SCloudaccount) StartSyncCloudProviderInfoTask(ctx context.Context, u
log.Errorf("CloudAccountSyncInfoTask newTask error %s", err)
return err
}
self.markStartSync(userCred)
self.markStartSync(userCred, syncRange)
db.OpsLog.LogEvent(self, db.ACT_SYNC_HOST_START, "", userCred)
task.ScheduleRun(nil)
return nil
}
func (self *SCloudaccount) markStartSync(userCred mcclient.TokenCredential) error {
func (self *SCloudaccount) markStartSync(userCred mcclient.TokenCredential, syncRange *SSyncRange) error {
_, err := db.Update(self, func() error {
self.SyncStatus = api.CLOUD_PROVIDER_SYNC_STATUS_QUEUED
return nil
@@ -567,7 +568,7 @@ func (self *SCloudaccount) markStartSync(userCred mcclient.TokenCredential) erro
providers := self.GetCloudproviders()
for i := range providers {
if providers[i].Enabled {
err := providers[i].markStartingSync(userCred)
err := providers[i].markStartingSync(userCred, syncRange)
if err != nil {
return errors.Wrap(err, "providers.markStartSync")
}
@@ -594,9 +595,9 @@ func (self *SCloudaccount) MarkEndSyncWithLock(ctx context.Context, userCred mcc
lockman.LockObject(ctx, self)
defer lockman.ReleaseObject(ctx, self)
if self.SyncStatus == api.CLOUD_PROVIDER_SYNC_STATUS_IDLE {
return nil
}
// if self.SyncStatus == api.CLOUD_PROVIDER_SYNC_STATUS_IDLE {
// return nil
// }
providers := self.GetCloudproviders()
for i := range providers {
@@ -717,7 +718,7 @@ func (self *SCloudaccount) importSubAccount(ctx context.Context, userCred mcclie
ownerId = userCred
} else {
// find default project of domain
t, err := db.TenantCacheManager.FindFirstProjectOfDomain(ownerId.GetProjectDomainId())
t, err := db.TenantCacheManager.FindFirstProjectOfDomain(ctx, ownerId.GetProjectDomainId())
if err != nil {
log.Errorf("cannot find a valid porject for domain %s", ownerId.GetProjectDomainId())
return nil, err
@@ -1380,6 +1381,18 @@ func (manager *SCloudaccountManager) initAllRecords() {
}
}
func (self *SCloudaccount) CanSync() bool {
if self.SyncStatus == api.CLOUD_PROVIDER_SYNC_STATUS_QUEUED || self.SyncStatus == api.CLOUD_PROVIDER_SYNC_STATUS_SYNCING || self.getSyncStatus2() == api.CLOUD_PROVIDER_SYNC_STATUS_SYNCING {
if self.LastSync.IsZero() || time.Now().Sub(self.LastSync) > 1800*time.Second {
return true
} else {
return false
}
} else {
return true
}
}
func (manager *SCloudaccountManager) AutoSyncCloudaccountTask(ctx context.Context, userCred mcclient.TokenCredential, isStart bool) {
if isStart && !options.Options.IsSlaveNode {
// mark all the records to be idle
@@ -1415,7 +1428,7 @@ func (account *SCloudaccount) probeAccountStatus(ctx context.Context, userCred m
manager, err := account.getProviderInternal()
if err != nil {
log.Errorf("account.GetProvider failed: %s", err)
return nil, err
return nil, errors.Wrap(err, "account.getProviderInternal")
}
balance, status, err := manager.GetBalance()
if err != nil {
@@ -1433,7 +1446,7 @@ func (account *SCloudaccount) probeAccountStatus(ctx context.Context, userCred m
sysInfo, err := manager.GetSysInfo()
if err != nil {
log.Errorf("manager.GetSysInfo fail %s", err)
return nil, err
return nil, errors.Wrap(err, "manager.GetSysInfo")
}
factory := manager.GetFactory()
diff, err := db.Update(account, func() error {
@@ -1487,7 +1500,7 @@ func (account *SCloudaccount) syncAccountStatus(ctx context.Context, userCred mc
if err != nil {
account.markAllProvidersDicconnected(ctx, userCred)
account.markAccountDiscconected(ctx, userCred)
return err
return errors.Wrap(err, "account.probeAccountStatus")
}
account.markAccountConnected(ctx, userCred)
providers := account.importAllSubaccounts(ctx, userCred, subaccounts)
@@ -1496,7 +1509,7 @@ func (account *SCloudaccount) syncAccountStatus(ctx context.Context, userCred mc
_, err := providers[i].prepareCloudproviderRegions(ctx, userCred)
if err != nil {
log.Errorf("syncCloudproviderRegion fail %s", err)
return err
return errors.Wrap(err, "providers[i].prepareCloudproviderRegions")
}
}
}
@@ -1515,13 +1528,39 @@ func (account *SCloudaccount) markAutoSync(userCred mcclient.TokenCredential) er
return nil
}
var (
cloudaccountPendingSyncs = map[string]struct{}{}
cloudaccountPendingSyncsMutex = &sync.Mutex{}
)
func (account *SCloudaccount) SubmitSyncAccountTask(ctx context.Context, userCred mcclient.TokenCredential, waitChan chan error, autoSync bool) {
cloudaccountPendingSyncsMutex.Lock()
defer cloudaccountPendingSyncsMutex.Unlock()
if _, ok := cloudaccountPendingSyncs[account.Id]; ok {
if waitChan != nil {
go func() {
// an active cloudaccount sync task is running, return with conflict error
log.Errorf("an active cloudaccount sync task is running, early return with conflict error")
waitChan <- errors.Wrap(httperrors.ErrConflict, "cloudaccountPendingSyncs")
}()
}
return
}
cloudaccountPendingSyncs[account.Id] = struct{}{}
RunSyncCloudAccountTask(func() {
func() {
cloudaccountPendingSyncsMutex.Lock()
defer cloudaccountPendingSyncsMutex.Unlock()
delete(cloudaccountPendingSyncs, account.Id)
}()
log.Debugf("syncAccountStatus %s %s", account.Id, account.Name)
err := account.syncAccountStatus(ctx, userCred)
if waitChan != nil {
if err != nil {
account.markEndSync(userCred)
err = errors.Wrap(err, "account.syncAccountStatus")
}
waitChan <- err
} else {
@@ -1531,7 +1570,8 @@ func (account *SCloudaccount) SubmitSyncAccountTask(ctx context.Context, userCre
account.markAutoSync(userCred)
providers := account.GetEnabledCloudproviders()
for i := range providers {
providers[i].syncCloudproviderRegions(ctx, userCred, syncRange, nil, autoSync)
provider := &providers[i]
provider.syncCloudproviderRegions(ctx, userCred, syncRange, nil, autoSync)
syncCnt += 1
}
}

View File

@@ -26,12 +26,14 @@ import (
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/compare"
"yunion.io/x/pkg/util/timeutils"
"yunion.io/x/pkg/utils"
"yunion.io/x/sqlchemy"
api "yunion.io/x/onecloud/pkg/apis/compute"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/nopanic"
)
type SCloudproviderregionManager struct {
@@ -225,17 +227,23 @@ func (manager *SCloudproviderregionManager) FetchByIdsOrCreate(providerId string
return cpr
}
func (self *SCloudproviderregion) markStartingSync(userCred mcclient.TokenCredential) error {
func (self *SCloudproviderregion) markStartingSync(userCred mcclient.TokenCredential, syncRange *SSyncRange) error {
if !self.Enabled {
return fmt.Errorf("Cloudprovider(%s)region(%s) disabled", self.CloudproviderId, self.CloudregionId)
}
_, err := db.Update(self, func() error {
self.SyncStatus = api.CLOUD_PROVIDER_SYNC_STATUS_QUEUING
return nil
})
if err != nil {
log.Errorf("Failed to markStartingSync error: %v", err)
return err
regionIds := []string{}
if syncRange != nil {
regionIds, _ = syncRange.GetRegionIds()
}
if syncRange == nil || len(regionIds) == 0 || utils.IsInStringArray(self.CloudregionId, regionIds) {
_, err := db.Update(self, func() error {
self.SyncStatus = api.CLOUD_PROVIDER_SYNC_STATUS_QUEUING
return nil
})
if err != nil {
log.Errorf("Failed to markStartingSync error: %v", err)
return err
}
}
return nil
}
@@ -385,10 +393,12 @@ func (self *SCloudproviderregion) getSyncTaskKey() string {
func (self *SCloudproviderregion) submitSyncTask(userCred mcclient.TokenCredential, syncRange SSyncRange, waitChan chan bool) {
self.markStartSync(userCred)
RunSyncCloudproviderRegionTask(self.getSyncTaskKey(), func() {
err := self.DoSync(context.Background(), userCred, syncRange)
if err != nil {
log.Errorf("DoSync faild %v", err)
}
nopanic.Run(func() {
err := self.DoSync(context.Background(), userCred, syncRange)
if err != nil {
log.Errorf("DoSync faild %v", err)
}
})
if waitChan != nil {
waitChan <- true
}

View File

@@ -380,6 +380,44 @@ type SSyncRange struct {
Host []string
}
func (sr *SSyncRange) GetRegionIds() ([]string, error) {
regionIds := []string{}
if len(sr.Host) == 0 && len(sr.Zone) == 0 && len(sr.Region) == 0 {
return regionIds, nil
}
hostQ := HostManager.Query().SubQuery()
hosts := hostQ.Query().Filter(sqlchemy.OR(
sqlchemy.In(hostQ.Field("id"), sr.Host),
sqlchemy.In(hostQ.Field("name"), sr.Host),
)).SubQuery()
zoneQ := ZoneManager.Query().SubQuery()
zones := zoneQ.Query().Filter(sqlchemy.OR(
sqlchemy.In(zoneQ.Field("id"), sr.Zone),
sqlchemy.In(zoneQ.Field("name"), sr.Zone),
sqlchemy.In(zoneQ.Field("id"), hosts.Query(hosts.Field("zone_id")).SubQuery()),
)).SubQuery()
regionQ := CloudregionManager.Query().SubQuery()
q := regionQ.Query(regionQ.Field("id")).Filter(sqlchemy.OR(
sqlchemy.In(regionQ.Field("id"), sr.Region),
sqlchemy.In(regionQ.Field("name"), sr.Region),
sqlchemy.In(regionQ.Field("id"), zones.Query(zones.Field("cloudregion_id")).SubQuery()),
))
rows, err := q.Rows()
if err != nil {
return nil, errors.Wrap(err, "q.Rows")
}
defer rows.Close()
for rows.Next() {
var regionId string
err = rows.Scan(&regionId)
if err != nil {
return nil, errors.Wrap(err, "rows.Scan")
}
regionIds = append(regionIds, regionId)
}
return regionIds, nil
}
func (sr *SSyncRange) NeedSyncInfo() bool {
if sr.FullSync {
return true
@@ -535,7 +573,7 @@ func (self *SCloudprovider) StartSyncCloudProviderInfoTask(ctx context.Context,
cloudaccount.markAutoSync(userCred)
cloudaccount.MarkSyncing(userCred)
}
self.markStartSync(userCred)
self.markStartSync(userCred, syncRange)
db.OpsLog.LogEvent(self, db.ACT_SYNC_HOST_START, "", userCred)
task.ScheduleRun(nil)
return nil
@@ -602,7 +640,7 @@ func (self *SCloudprovider) PerformChangeProject(ctx context.Context, userCred m
return nil, self.StartSyncCloudProviderInfoTask(ctx, userCred, &SSyncRange{FullSync: true, DeepSync: true}, "")
}
func (self *SCloudprovider) markStartingSync(userCred mcclient.TokenCredential) error {
func (self *SCloudprovider) markStartingSync(userCred mcclient.TokenCredential, syncRange *SSyncRange) error {
_, err := db.Update(self, func() error {
self.SyncStatus = api.CLOUD_PROVIDER_SYNC_STATUS_QUEUING
return nil
@@ -614,7 +652,7 @@ func (self *SCloudprovider) markStartingSync(userCred mcclient.TokenCredential)
cprs := self.GetCloudproviderRegions()
for i := range cprs {
if cprs[i].Enabled {
err := cprs[i].markStartingSync(userCred)
err := cprs[i].markStartingSync(userCred, syncRange)
if err != nil {
return errors.Wrap(err, "cprs[i].markStartingSync")
}
@@ -623,7 +661,7 @@ func (self *SCloudprovider) markStartingSync(userCred mcclient.TokenCredential)
return nil
}
func (self *SCloudprovider) markStartSync(userCred mcclient.TokenCredential) error {
func (self *SCloudprovider) markStartSync(userCred mcclient.TokenCredential, syncRange *SSyncRange) error {
_, err := db.Update(self, func() error {
self.SyncStatus = api.CLOUD_PROVIDER_SYNC_STATUS_QUEUED
return nil
@@ -635,7 +673,7 @@ func (self *SCloudprovider) markStartSync(userCred mcclient.TokenCredential) err
cprs := self.GetCloudproviderRegions()
for i := range cprs {
if cprs[i].Enabled {
err := cprs[i].markStartingSync(userCred)
err := cprs[i].markStartingSync(userCred, syncRange)
if err != nil {
return errors.Wrap(err, "cprs[i].markStartingSync")
}
@@ -1118,9 +1156,10 @@ func (provider *SCloudprovider) GetCloudproviderRegions() []SCloudproviderregion
func (provider *SCloudprovider) syncCloudproviderRegions(ctx context.Context, userCred mcclient.TokenCredential, syncRange SSyncRange, wg *sync.WaitGroup, autoSync bool) {
provider.markSyncing(userCred)
cprs := provider.GetCloudproviderRegions()
regionIds, _ := syncRange.GetRegionIds()
syncCnt := 0
for i := range cprs {
if cprs[i].Enabled && cprs[i].CanSync() && (!autoSync || cprs[i].needAutoSync()) {
if cprs[i].Enabled && cprs[i].CanSync() && (!autoSync || cprs[i].needAutoSync()) && (len(regionIds) == 0 || utils.IsInStringArray(cprs[i].CloudregionId, regionIds)) {
syncCnt += 1
var waitChan chan bool = nil
if wg != nil {
@@ -1217,6 +1256,14 @@ func (self *SCloudprovider) StartCloudproviderDeleteTask(ctx context.Context, us
return nil
}
func (self *SCloudprovider) GetRegionDriver() (IRegionDriver, error) {
driver := GetRegionDriver(self.Provider)
if driver == nil {
return nil, fmt.Errorf("failed to found region driver for %s", self.Provider)
}
return driver, nil
}
func (self *SCloudprovider) ClearSchedDescCache() error {
hosts := make([]SHost, 0)
q := HostManager.Query().Equals("manager_id", self.Id)

View File

@@ -400,6 +400,9 @@ func (self *SCloudregion) syncWithCloudRegion(ctx context.Context, userCred mccl
}
diff, err := db.UpdateWithLock(ctx, self, func() error {
if !utils.IsInStringArray(self.Provider, api.PRIVATE_CLOUD_PROVIDERS) {
self.Name = cloudRegion.GetName()
}
self.Status = cloudRegion.GetStatus()
self.SGeographicInfo = cloudRegion.GetGeographicInfo()
self.Provider = cloudRegion.GetProvider()

View File

@@ -59,7 +59,7 @@ type SDBInstanceAccount struct {
db.SStatusStandaloneResourceBase
db.SExternalizedResourceBase
Secret string `width:"256" charset:"ascii" nullable:"false" list:"domain" create:"optional"`
Secret string `width:"256" charset:"ascii" nullable:"false" list:"user" create:"optional"`
DBInstanceId string `width:"36" charset:"ascii" name:"dbinstance_id" nullable:"false" list:"user" create:"required" index:"true"`
}
@@ -98,7 +98,7 @@ func (manager *SDBInstanceAccountManager) FetchOwnerId(ctx context.Context, data
}
return instance.(*SDBInstance).GetOwnerId(), nil
}
return nil, nil
return db.FetchProjectInfo(ctx, data)
}
func (manager *SDBInstanceAccountManager) FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {

View File

@@ -95,7 +95,7 @@ func (manager *SDBInstanceDatabaseManager) FetchOwnerId(ctx context.Context, dat
}
return instance.(*SDBInstance).GetOwnerId(), nil
}
return nil, nil
return db.FetchProjectInfo(ctx, data)
}
func (manager *SDBInstanceDatabaseManager) FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {

View File

@@ -59,7 +59,7 @@ type SDBInstanceSku struct {
SCloudregionResourceBase
Provider string `width:"32" charset:"ascii" nullable:"false" list:"user" create:"admin_required" update:"admin"`
StorageType string `list:"user" create:"optional"`
StorageType string `width:"32" index:"true" list:"user" create:"optional"`
DiskSizeStep int `list:"user" default:"1" create:"optional"` //步长
MaxDiskSizeGb int `list:"user" create:"optional"`
MinDiskSizeGb int `list:"user" create:"optional"`
@@ -72,9 +72,9 @@ type SDBInstanceSku struct {
VcpuCount int `nullable:"false" default:"1" list:"user" create:"optional"`
VmemSizeMb int `nullable:"false" list:"user" create:"required"`
Category string `nullable:"false" list:"user" create:"optional"`
Engine string `width:"16" charset:"ascii" nullable:"false" list:"user" create:"required"`
EngineVersion string `width:"16" charset:"ascii" nullable:"false" list:"user" create:"required"`
Category string `width:"32" index:"true" nullable:"false" list:"user" create:"optional"`
Engine string `width:"16" index:"true" charset:"ascii" nullable:"false" list:"user" create:"required"`
EngineVersion string `width:"16" index:"true" charset:"ascii" nullable:"false" list:"user" create:"required"`
Zone1 string `width:"128" charset:"ascii" nullable:"false" list:"user" create:"admin_optional" update:"admin"`
Zone2 string `width:"128" charset:"ascii" nullable:"false" list:"user" create:"admin_optional" update:"admin"`

View File

@@ -1131,9 +1131,12 @@ func (self *SDBInstance) syncRemoveCloudDBInstance(ctx context.Context, userCred
lockman.LockObject(ctx, self)
defer lockman.ReleaseObject(ctx, self)
self.DeletePreventionOff(self, userCred)
err := self.ValidateDeleteCondition(ctx)
if err != nil { // cannot delete
return self.SetStatus(userCred, api.VPC_STATUS_UNKNOWN, "sync to delete")
self.SetStatus(userCred, api.VPC_STATUS_UNKNOWN, "sync to delete")
return errors.Wrap(err, "ValidateDeleteCondition")
}
return self.RealDelete(ctx, userCred)
}

View File

@@ -492,7 +492,9 @@ func (manager *SDiskManager) ValidateCreateData(ctx context.Context, userCred mc
input.Hypervisor,
)
} else {
diskConfig.Backend = api.STORAGE_LOCAL
if len(diskConfig.Backend) == 0 {
diskConfig.Backend = api.STORAGE_LOCAL
}
serverInput, err := ValidateScheduleCreateData(ctx, userCred, input.ToServerCreateInput(), input.Hypervisor)
if err != nil {
return nil, err
@@ -901,6 +903,9 @@ func (disk *SDisk) doResize(ctx context.Context, userCred mcclient.TokenCredenti
}
addDisk := sizeMb - disk.DiskSize
storage := disk.GetStorage()
if storage == nil {
return httperrors.NewInternalServerError("disk has no valid storage")
}
if host := storage.GetMasterHost(); host != nil {
if err := host.GetHostDriver().ValidateDiskSize(storage, sizeMb>>10); err != nil {
return httperrors.NewInputParameterError(err.Error())
@@ -1055,6 +1060,17 @@ func (self *SDisk) ValidatePurgeCondition(ctx context.Context) error {
}
func (self *SDisk) validateDeleteCondition(ctx context.Context, isPurge bool) error {
if !isPurge {
storage := self.GetStorage()
if storage == nil {
// storage is empty, a dirty data, allow delete
return nil
}
host := storage.GetMasterHost()
if host == nil {
return httperrors.NewBadRequestError("storage of disk no valid host")
}
}
cnt, err := self.GetGuestDiskCount()
if err != nil {
return httperrors.NewInternalServerError("GetGuestDiskCount fail %s", err)
@@ -1162,6 +1178,9 @@ func (self *SDisk) GetPathAtHost(host *SHost) string {
func (self *SDisk) GetFetchUrl() string {
storage := self.GetStorage()
if storage == nil {
return ""
}
host := storage.GetMasterHost()
return fmt.Sprintf("%s/disks/%s", host.GetFetchUrl(true), self.Id)
}
@@ -1190,7 +1209,10 @@ func (manager *SDiskManager) syncCloudDisk(ctx context.Context, userCred mcclien
diskObj, err := db.FetchByExternalId(manager, vdisk.GetGlobalId())
if err != nil {
if err == sql.ErrNoRows {
vstorage, _ := vdisk.GetIStorage()
vstorage, err := vdisk.GetIStorage()
if err != nil {
return nil, errors.Wrapf(err, "unable to GetIStorage of vdisk %q", vdisk.GetName())
}
storageObj, err := db.FetchByExternalId(StorageManager, vstorage.GetGlobalId())
if err != nil {
@@ -1387,7 +1409,6 @@ func (self *SDisk) syncWithCloudDisk(ctx context.Context, userCred mcclient.Toke
}
extDisk.Refresh()
storage := self.GetStorage()
diff, err := db.UpdateWithLock(ctx, self, func() error {
// self.Name = extDisk.GetName()
self.Status = extDisk.GetStatus()
@@ -1414,8 +1435,12 @@ func (self *SDisk) syncWithCloudDisk(ctx context.Context, userCred mcclient.Toke
self.IsEmulated = extDisk.IsEmulated()
if provider.GetFactory().IsSupportPrepaidResources() && !recycle {
self.BillingType = extDisk.GetBillingType()
self.ExpiredAt = extDisk.GetExpiredAt()
if billintType := extDisk.GetBillingType(); len(billintType) > 0 {
self.BillingType = extDisk.GetBillingType()
}
if expiredAt := extDisk.GetExpiredAt(); !expiredAt.IsZero() {
self.ExpiredAt = extDisk.GetExpiredAt()
}
}
if createdAt := extDisk.GetCreatedAt(); !createdAt.IsZero() {
@@ -1434,6 +1459,10 @@ func (self *SDisk) syncWithCloudDisk(ctx context.Context, userCred mcclient.Toke
if err != nil {
return errors.Wrapf(err, "Get snapshot policies of ICloudDisk %s.", extDisk.GetId())
}
storage := self.GetStorage()
if storage == nil {
return fmt.Errorf("no valid storage")
}
err = SnapshotPolicyDiskManager.SyncByDisk(ctx, userCred, snapshotpolicies, syncOwnerId, self, storage)
if err != nil {
return err
@@ -1591,7 +1620,7 @@ func parseDiskInfo(ctx context.Context, userCred mcclient.TokenCredential, info
// diskConfig.SizeMb = options.Options.DefaultDiskSize // MB
// else
if len(info.ImageId) == 0 && info.SizeMb == 0 {
return nil, httperrors.NewInputParameterError("Diskinfo not contains either imageID or size")
return nil, httperrors.NewInputParameterError("Diskinfo index %d: both imageID and size are absent", info.Index)
}
return info, nil
}
@@ -1988,6 +2017,9 @@ func (self *SDisk) SwitchToBackup(userCred mcclient.TokenCredential) error {
func (self *SDisk) ClearHostSchedCache() error {
storage := self.GetStorage()
if storage == nil {
return fmt.Errorf("no valid storage")
}
hosts := storage.GetAllAttachingHosts()
if hosts == nil {
return fmt.Errorf("get attaching host error")
@@ -2147,7 +2179,11 @@ func (disk *SDisk) validateDiskAutoCreateSnapshot() error {
if len(guests) == 0 {
return fmt.Errorf("Disks %s not attach guest, can't create snapshot", disk.GetName())
}
if len(guests) == 1 && utils.IsInStringArray(disk.GetStorage().StorageType, api.FIEL_STORAGE) {
storage := disk.GetStorage()
if storage == nil {
return fmt.Errorf("no valid storage")
}
if len(guests) == 1 && utils.IsInStringArray(storage.StorageType, api.FIEL_STORAGE) {
if !utils.IsInStringArray(guests[0].Status, []string{api.VM_RUNNING, api.VM_READY}) {
return fmt.Errorf("Guest(%s) in status(%s) cannot do disk snapshot", guests[0].Id, guests[0].Status)
}
@@ -2328,6 +2364,9 @@ func (self *SDisk) GetDynamicConditionInput() *jsonutils.JSONDict {
func (self *SDisk) IsNeedWaitSnapshotsDeleted() (bool, error) {
storage := self.GetStorage()
if storage == nil {
return false, fmt.Errorf("no valid storage")
}
if storage.StorageType == api.STORAGE_RBD {
scnt, err := self.GetSnapshotCount()
if err != nil {
@@ -2394,7 +2433,12 @@ func (self *SDisk) syncSnapshots(ctx context.Context, userCred mcclient.TokenCre
}
provider := self.GetCloudprovider()
syncOwnerId := provider.GetOwnerId()
region := self.GetStorage().GetRegion()
storage := self.GetStorage()
if storage == nil {
syncResult.Error(fmt.Errorf("no valid storage"))
return syncResult
}
region := storage.GetRegion()
extSnapshots, err := extDisk.GetISnapshots()
if err != nil {

View File

@@ -36,6 +36,8 @@ type SDnsRecordManager struct {
db.SAdminSharableVirtualResourceBaseManager
}
var _ db.IAdminSharableVirtualModelManager = DnsRecordManager
var DnsRecordManager *SDnsRecordManager
func init() {
@@ -275,35 +277,38 @@ func (man *SDnsRecordManager) checkRecordValue(typ, val string) error {
func (man *SDnsRecordManager) validateModelData(
ctx context.Context,
userCred mcclient.TokenCredential,
ownerId mcclient.IIdentityProvider,
query jsonutils.JSONObject,
data *jsonutils.JSONDict,
) (*jsonutils.JSONDict, error) {
records, err := man.ParseInputInfo(data)
isCreate bool,
) (records []string, err error) {
data.Remove("records")
records, err = man.ParseInputInfo(data)
if err != nil {
return nil, err
return
}
if len(records) == 0 {
return nil, httperrors.NewInputParameterError("Empty record")
if isCreate {
err = httperrors.NewInputParameterError("Empty record")
return
}
return
}
recType := man.getRecordsType(records)
name, err := data.GetString("name")
if err != nil {
return nil, err
return
}
err = man.checkRecordName(recType, name)
if err != nil {
return nil, err
return
}
if data.Contains("ttl") {
jo, err := data.Get("ttl")
var (
ttl int64
)
ttl, err = data.Int("ttl")
if err != nil {
return nil, err
}
ttl, err := jo.Int()
if err != nil {
return nil, httperrors.NewInputParameterError("invalid ttl: %s", err)
err = httperrors.NewInputParameterError("invalid ttl: %s", err)
return
}
if ttl == 0 {
// - Create: use the database default
@@ -311,10 +316,11 @@ func (man *SDnsRecordManager) validateModelData(
data.Remove("ttl")
} else if ttl < 0 || ttl > 0x7fffffff {
// positive values of a signed 32 bit number.
return nil, httperrors.NewInputParameterError("invalid ttl: %d", ttl)
err = httperrors.NewInputParameterError("invalid ttl: %d", ttl)
return
}
}
return data, err
return records, nil
}
func (man *SDnsRecordManager) ValidateCreateData(
@@ -324,7 +330,7 @@ func (man *SDnsRecordManager) ValidateCreateData(
query jsonutils.JSONObject,
data *jsonutils.JSONDict,
) (*jsonutils.JSONDict, error) {
data, err := man.validateModelData(ctx, userCred, ownerId, query, data)
_, err := man.validateModelData(ctx, data, true)
if err != nil {
return nil, err
}
@@ -401,15 +407,11 @@ func (rec *SDnsRecord) GetInfo() []string {
func (rec *SDnsRecord) ValidateUpdateData(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data *jsonutils.JSONDict) (*jsonutils.JSONDict, error) {
data.UpdateDefault(jsonutils.Marshal(rec))
data, err := DnsRecordManager.validateModelData(ctx, userCred, rec.GetOwnerId(), query, data)
records, err := DnsRecordManager.validateModelData(ctx, data, false)
if err != nil {
return nil, err
}
{
records, err := DnsRecordManager.ParseInputInfo(data)
if err != nil {
return nil, err
}
if len(records) > 0 {
data.Set("records", jsonutils.NewString(strings.Join(records, DNS_RECORDS_SEPARATOR)))
}
return rec.SAdminSharableVirtualResourceBase.ValidateUpdateData(ctx, userCred, query, data)

View File

@@ -116,7 +116,7 @@ func elasticcacheSubResourceFetchOwnerId(ctx context.Context, data jsonutils.JSO
return ec.(*SElasticcache).GetOwnerId(), nil
}
return nil, nil
return db.FetchProjectInfo(ctx, data)
}
// elastic cache 子资源获取owner query
@@ -329,9 +329,12 @@ func (self *SElasticcache) syncRemoveCloudElasticcache(ctx context.Context, user
lockman.LockObject(ctx, self)
defer lockman.ReleaseObject(ctx, self)
self.DeletePreventionOff(self, userCred)
err := self.ValidateDeleteCondition(ctx)
if err != nil {
return self.SetStatus(userCred, api.ELASTIC_CACHE_STATUS_ERROR, "sync to delete")
self.SetStatus(userCred, api.ELASTIC_CACHE_STATUS_ERROR, "sync to delete")
return errors.Wrap(err, "ValidateDeleteCondition")
}
return self.Delete(ctx, userCred)
}

View File

@@ -185,8 +185,10 @@ func (self *SExternalProject) SyncWithCloudProject(ctx context.Context, userCred
diff, err := db.UpdateWithLock(ctx, self, func() error {
self.Name = ext.GetName()
self.IsEmulated = ext.IsEmulated()
self.ProjectId = provider.ProjectId
self.DomainId = provider.DomainId
if self.DomainId != provider.DomainId {
self.ProjectId = provider.ProjectId
self.DomainId = provider.DomainId
}
return nil
})
if err != nil {

View File

@@ -3915,6 +3915,20 @@ func (self *SGuest) PerformSyncFixNics(ctx context.Context,
return nil, httperrors.NewInputParameterError("missing field ip, list of ip")
}
iplist := iplistArray.(*jsonutils.JSONArray).GetStringArray()
errs := make([]error, 0)
for i := range vnics {
ip := vnics[i].GetIP()
if len(ip) == 0 {
continue
}
_, err := host.getNetworkOfIPOnHost(ip)
if err != nil {
errs = append(errs, errors.Wrap(err, ip))
}
}
if len(errs) > 0 {
return nil, httperrors.NewInvalidStatusError(errors.NewAggregate(errs).Error())
}
result := self.SyncVMNics(ctx, userCred, host, vnics, iplist)
if result.IsError() {
return nil, httperrors.NewInternalServerError(result.Result())
@@ -4385,6 +4399,9 @@ func (self *SGuest) PerformSnapshotAndClone(
quotas.CancelPendingUsage(ctx, userCred, &pendingUsage, &pendingUsage, false)
quotas.CancelPendingUsage(ctx, userCred, &pendingRegionUsage, &pendingRegionUsage, false)
return nil, httperrors.NewInternalServerError("create instance snapshot failed: %s", err)
} else {
cancelRegionUsage := &SRegionQuota{Snapshot: snapshotUsage.Snapshot}
quotas.CancelPendingUsage(ctx, userCred, &pendingRegionUsage, cancelRegionUsage, true)
}
err = self.StartInstanceSnapshotAndCloneTask(

View File

@@ -183,15 +183,11 @@ func (self *SGuestdisk) GetJsonDescAtHost(host *SHost) jsonutils.JSONObject {
desc.Add(jsonutils.NewString(storagecacheimg.Path), "image_path")
}
}
storage := disk.GetStorage()
// XXX ???
if host.HostType == api.HOST_TYPE_HYPERVISOR {
desc.Add(jsonutils.NewString(disk.StorageId), "storage_id")
localpath := disk.GetPathAtHost(host)
if len(localpath) == 0 {
desc.Add(jsonutils.JSONTrue, "migrating")
target := host.GetLeastUsedStorage(storage.StorageType)
desc.Add(jsonutils.NewString(target.Id), "target_storage_id")
disk.SetStatus(nil, api.DISK_START_MIGRATE, "migration")
} else {
desc.Add(jsonutils.NewString(localpath), "path")

View File

@@ -16,11 +16,9 @@ package models
import (
"context"
"crypto/md5"
"crypto/rand"
"database/sql"
"fmt"
"io"
"math/rand"
"regexp"
"time"
@@ -37,6 +35,7 @@ import (
"yunion.io/x/onecloud/pkg/compute/options"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
randutil "yunion.io/x/onecloud/pkg/util/rand"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
@@ -226,17 +225,6 @@ func (manager *SGuestnetworkManager) newGuestNetwork(ctx context.Context, userCr
return &gn, nil
}
func (self *SGuestnetwork) getVirtualRand(width int, randomized bool) string {
hash := md5.New()
io.WriteString(hash, self.GuestId)
io.WriteString(hash, self.NetworkId)
if randomized {
io.WriteString(hash, fmt.Sprintf("%d", time.Now().Unix()))
}
hex := fmt.Sprintf("%x", hash.Sum(nil))
return hex[:width]
}
func (self *SGuestnetwork) generateIfname(network *SNetwork, virtual bool, randomized bool) string {
// It may happen that external networks when synced can miss ifname hint
network.ensureIfnameHint()
@@ -247,8 +235,7 @@ func (self *SGuestnetwork) generateIfname(network *SNetwork, virtual bool, rando
nName = nName[:(MAX_IFNAME_SIZE - 4)]
}
if virtual {
rand := self.getVirtualRand(3, randomized)
return fmt.Sprintf("%s-%s", nName, rand)
return fmt.Sprintf("%s-%s", nName, randutil.String(3))
} else {
ip, _ := netutils.NewIPV4Addr(self.IpAddr)
cliaddr := ip.CliAddr(network.GuestIpMask)

View File

@@ -1129,6 +1129,9 @@ func (manager *SGuestManager) validateCreateData(
rootDiskConfig.SizeMb = sysMinDiskMB
}
}
if len(rootDiskConfig.Driver) == 0 {
rootDiskConfig.Driver = osProf.DiskDriver
}
log.Debugf("ROOT DISK: %#v", rootDiskConfig)
input.Disks[0] = rootDiskConfig
//data.Set("disk.0", jsonutils.Marshal(rootDiskConfig))
@@ -1518,10 +1521,13 @@ func (guest *SGuest) PostCreate(ctx context.Context, userCred mcclient.TokenCred
guest.setUserData(ctx, userCred, userData)
}
secgroups, _ := jsonutils.GetStringArray(data, "secgroups")
for _, secgroup := range secgroups {
gs := SGuestsecgroup{SecgroupId: secgroup}
gs.GuestId = guest.Id
GuestsecgroupManager.TableSpec().Insert(&gs)
for _, secgroupId := range secgroups {
if secgroupId != guest.SecgrpId {
gs := SGuestsecgroup{}
gs.SecgroupId = secgroupId
gs.GuestId = guest.Id
GuestsecgroupManager.TableSpec().Insert(&gs)
}
}
}
@@ -3205,14 +3211,19 @@ func (self *SGuest) createDiskOnStorage(ctx context.Context, userCred mcclient.T
return nil, err
}
cancelUsage := SQuota{}
cancelUsage.Storage = disk.DiskSize
keys, err := self.GetQuotaKeys()
if err != nil {
return nil, err
if pendingUsage != nil {
cancelUsage := SQuota{}
cancelUsage.Storage = disk.DiskSize
keys, err := self.GetQuotaKeys()
if err != nil {
return nil, err
}
cancelUsage.SetKeys(keys)
err = quotas.CancelPendingUsage(ctx, userCred, pendingUsage, &cancelUsage, true)
if err != nil {
return nil, err
}
}
cancelUsage.SetKeys(keys)
err = quotas.CancelPendingUsage(ctx, userCred, pendingUsage, &cancelUsage, true)
return disk, nil
}
@@ -4701,7 +4712,9 @@ func (self *SGuest) ToCreateInput(userCred mcclient.TokenCredential) *api.Server
for idx, disk := range genInput.Disks {
tmpD := disk
if idx < len(userInput.Disks) {
tmpD.Schedtags = userInput.Disks[idx].Schedtags
inputDisk := userInput.Disks[idx]
tmpD.Schedtags = inputDisk.Schedtags
tmpD.Storage = inputDisk.Storage
}
disks = append(disks, tmpD)
}
@@ -4711,7 +4724,9 @@ func (self *SGuest) ToCreateInput(userCred mcclient.TokenCredential) *api.Server
for idx, net := range genInput.Networks {
tmpN := net
if idx < len(userInput.Networks) {
tmpN.Schedtags = userInput.Disks[idx].Schedtags
inputNet := userInput.Networks[idx]
tmpN.Schedtags = inputNet.Schedtags
tmpN.Network = inputNet.Network
}
nets = append(nets, tmpN)
}

View File

@@ -53,7 +53,6 @@ import (
"yunion.io/x/onecloud/pkg/mcclient/modules"
"yunion.io/x/onecloud/pkg/util/httputils"
"yunion.io/x/onecloud/pkg/util/logclient"
"yunion.io/x/onecloud/pkg/util/redfish/bmconsole"
)
type SHostManager struct {
@@ -3631,10 +3630,16 @@ func (self *SHost) EnableNetif(ctx context.Context, userCred mcclient.TokenCrede
}
net, err = wire.GetCandidatePrivateNetwork(userCred, false, netTypes)
if err != nil {
return fmt.Errorf("fail to find network %s", err)
return fmt.Errorf("fail to find private network %s", err)
}
if net == nil {
return fmt.Errorf("No network found")
net, err = wire.GetCandidatePublicNetwork(false, netTypes)
if err != nil {
return fmt.Errorf("fail to find public network %s", err)
}
if net == nil {
return fmt.Errorf("No network found")
}
}
}
} else if net.WireId != wire.Id {
@@ -4585,39 +4590,13 @@ func (self *SHost) AllowGetDetailsJnlp(ctx context.Context, userCred mcclient.To
}
func (self *SHost) GetDetailsJnlp(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) (jsonutils.JSONObject, error) {
ipmi, err := self.GetIpmiInfo()
url := fmt.Sprintf("/baremetals/%s/jnlp", self.Id)
header := mcclient.GetTokenHeaders(userCred)
resp, err := self.BaremetalSyncRequest(ctx, "POST", url, header, nil)
if err != nil {
return nil, httperrors.NewInvalidStatusError("no valid ipmi_info")
return nil, errors.Wrap(err, "BaremetalSyncRequest")
}
if !ipmi.Verified {
return nil, httperrors.NewInvalidStatusError("no veried ipmi_info")
}
if self.SysInfo == nil {
return nil, httperrors.NewInvalidStatusError("no valid sys_info")
}
ipmiPass, err := utils.DescryptAESBase64(self.Id, ipmi.Password)
if err != nil {
return nil, httperrors.NewInternalServerError("decrypt ipmi password fail: %s", err)
}
bmc := bmconsole.NewBMCConsole(ipmi.IpAddr, ipmi.Username, ipmiPass, false)
manufacture, _ := self.SysInfo.GetString("manufacture")
var jnlp string
switch strings.ToLower(manufacture) {
case "hp", "hpe":
jnlp, err = bmc.GetIloConsoleJNLP(ctx)
case "dell", "dell inc.":
sku, _ := self.SysInfo.GetString("sku")
model, _ := self.SysInfo.GetString("model")
jnlp, err = bmc.GetIdracConsoleJNLP(ctx, sku, model)
default:
return nil, httperrors.NewNotImplementedError("Unsupported manufacture %s", manufacture)
}
if err != nil {
return nil, httperrors.NewGeneralError(err)
}
ret := jsonutils.NewDict()
ret.Add(jsonutils.NewString(jnlp), "jnlp")
return ret, nil
return resp, nil
}
func (self *SHost) AllowPerformInsertIso(ctx context.Context,

View File

@@ -147,6 +147,9 @@ func (p *SLoadbalancerAgentParamsVrrp) validatePeer(pp *SLoadbalancerAgentParams
if p.VirtualRouterId != pp.VirtualRouterId {
return fmt.Errorf("vrrp virtual_router_id of peer lbagents must be the same: %d != %d", p.VirtualRouterId, pp.VirtualRouterId)
}
if p.AdvertInt != pp.AdvertInt {
return fmt.Errorf("vrrp advert_int of peer lbagents must be the same: %d != %d", p.AdvertInt, pp.AdvertInt)
}
if p.Preempt != pp.Preempt {
return fmt.Errorf("vrrp preempt property of peer lbagents must be the same: %v != %v", p.Preempt, pp.Preempt)
}
@@ -161,6 +164,9 @@ func (p *SLoadbalancerAgentParamsVrrp) needsUpdatePeer(pp *SLoadbalancerAgentPar
if p.VirtualRouterId != pp.VirtualRouterId {
return true
}
if p.AdvertInt != pp.AdvertInt {
return true
}
if p.Preempt != pp.Preempt {
return true
}
@@ -172,6 +178,7 @@ func (p *SLoadbalancerAgentParamsVrrp) needsUpdatePeer(pp *SLoadbalancerAgentPar
func (p *SLoadbalancerAgentParamsVrrp) updateBy(pp *SLoadbalancerAgentParamsVrrp) {
p.VirtualRouterId = pp.VirtualRouterId
p.AdvertInt = pp.AdvertInt
p.Preempt = pp.Preempt
p.Pass = pp.Pass
}
@@ -431,9 +438,11 @@ func (man *SLoadbalancerAgentManager) CleanPendingDeleteLoadbalancers(ctx contex
}
agentsData := jsonutils.Marshal(&agents).(*jsonutils.JSONArray)
for fieldName, man := range men {
keyPlural := man.KeywordPlural()
now := time.Now()
minT := now
var (
keyPlural = man.KeywordPlural()
now = time.Now()
minT = now
)
if len(agents) > 0 {
// find min updated_at seen by these active agents
for i := 0; i < agentsData.Length(); i++ {
@@ -462,17 +471,13 @@ func (man *SLoadbalancerAgentManager) CleanPendingDeleteLoadbalancers(ctx contex
continue
}
defer rows.Close()
m, err := db.NewModelObject(man)
if err != nil {
log.Errorf("%s: new model object failed: %s", keyPlural, err)
continue
}
mInitValue := reflect.Indirect(reflect.ValueOf(m))
m, _ = db.NewModelObject(man)
for rows.Next() {
reflect.Indirect(reflect.ValueOf(m)).Set(mInitValue)
err := q.Row2Struct(rows, m)
m, err := db.NewModelObject(man)
if err != nil {
log.Errorf("%s: new model object failed: %s", keyPlural, err)
continue
}
if err := q.Row2Struct(rows, m); err != nil {
log.Errorf("%s: Row2Struct: %s", keyPlural, err)
continue
}

View File

@@ -159,7 +159,7 @@ func (lbagent *SLoadbalancerAgent) deploy(ctx context.Context, userCred mcclient
return nil, errors.WithMessagef(err, "glob error %s", pattern)
}
if len(matches) == 0 {
return nil, errors.WithMessagef(err, "glob nomatch %s", pattern)
return nil, errors.Errorf("no match for %q", pattern)
}
path := matches[len(matches)-1]
name := filepath.Base(path)
@@ -223,12 +223,9 @@ func (lbagent *SLoadbalancerAgent) undeploy(ctx context.Context, userCred mcclie
},
Modules: []ansible.Module{
{
Name: "systemd",
Name: "shell",
Args: []string{
"name=yunion-lbagent",
"enabled=no",
"state=stopped",
"daemon_reload=yes",
"systemctl disable --now yunion-lbagent; true",
},
},
{

View File

@@ -234,14 +234,8 @@ func (man *SAwsCachedLbbgManager) SyncLoadbalancerBackendgroups(ctx context.Cont
}
for i := 0; i < len(commondb); i++ {
var elb *SLoadbalancer
elbIds := commonext[i].GetLoadbalancerId()
if err != nil {
syncResult.UpdateError(err)
continue
}
elbId := commonext[i].GetLoadbalancerId()
if len(elbIds) > 0 {
if len(elbId) > 0 {
ielb, err := db.FetchByExternalId(LoadbalancerManager, elbId)
if err == nil {
elb = ielb.(*SLoadbalancer)
@@ -249,10 +243,8 @@ func (man *SAwsCachedLbbgManager) SyncLoadbalancerBackendgroups(ctx context.Cont
}
if elb == nil {
elb = &SLoadbalancer{}
elb.Id = ""
elb.CloudregionId = region.GetId()
elb.ManagerId = provider.GetId()
log.Debugf("Aws.SyncLoadbalancerBackendgroups skiped external backendgroup %s", elbId)
continue
}
err = commondb[i].SyncWithCloudLoadbalancerBackendgroup(ctx, userCred, elb, commonext[i], provider.GetOwnerId())
@@ -269,23 +261,18 @@ func (man *SAwsCachedLbbgManager) SyncLoadbalancerBackendgroups(ctx context.Cont
for i := 0; i < len(added); i++ {
var elb *SLoadbalancer
elbId := added[i].GetLoadbalancerId()
if err != nil {
syncResult.AddError(err)
continue
}
if len(elbId) > 0 {
elb, err = LoadbalancerManager.FetchByExternalId(provider.GetId(), elbId)
if err != nil {
log.Debugf("awsCachedLbbgManager.SyncLoadbalancerBackendgroups %s", err)
syncResult.AddError(err)
continue
}
}
if elb == nil {
elb = &SLoadbalancer{}
elb.Id = ""
elb.CloudregionId = region.GetId()
elb.ManagerId = provider.GetId()
log.Debugf("Aws.SyncLoadbalancerBackendgroups skiped external backendgroup %s", elbId)
continue
}
new, err := man.newFromCloudLoadbalancerBackendgroup(ctx, userCred, elb, added[i], syncOwnerId)

View File

@@ -101,6 +101,15 @@ func (man *SLoadbalancerBackendGroupManager) ListItemFilter(ctx context.Context,
return q, nil
}
func (man *SLoadbalancerBackendGroupManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
lbV := validators.NewModelIdOrNameValidator("loadbalancer", "loadbalancer", nil)
err := lbV.Validate(data.(*jsonutils.JSONDict))
if err == nil {
return lbV.Model.GetOwnerId(), nil
}
return man.SVirtualResourceBaseManager.FetchOwnerId(ctx, data)
}
func (man *SLoadbalancerBackendGroupManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data *jsonutils.JSONDict) (*jsonutils.JSONDict, error) {
lbV := validators.NewModelIdOrNameValidator("loadbalancer", "loadbalancer", ownerId)
err := lbV.Validate(data)
@@ -929,12 +938,29 @@ func (man *SLoadbalancerBackendGroupManager) initBackendGroupType() error {
}
func (man *SLoadbalancerBackendGroupManager) InitializeData() error {
if err := man.initBackendGroupType(); err != nil {
return err
q := man.Query().IsNullOrEmpty("loadbalancer_id")
lbbgs := make([]SLoadbalancerBackendGroup, 0)
err := db.FetchModelObjects(man, q, &lbbgs)
if err != nil {
return errors.Wrap(err, "SLoadbalancerBackendGroupManager.InitializeData")
}
return man.initBackendGroupRegion()
for i := range lbbgs {
lbbg := lbbgs[i]
_, err = db.UpdateWithLock(context.Background(), &lbbg, func() error {
lbbg.MarkDelete()
return nil
})
if err != nil {
return errors.Wrap(err, "SLoadbalancerBackendGroupManager.InitializeData.MarkDelete")
}
}
log.Debugf("SLoadbalancerBackendGroupManager.InitializeData removed %d invalid loadbalancer backendgroup.", len(lbbgs))
return nil
}
/*
func (manager *SLoadbalancerBackendGroupManager) initBackendGroupRegion() error {
groups := []SLoadbalancerBackendGroup{}
q := manager.Query()
@@ -956,7 +982,7 @@ func (manager *SLoadbalancerBackendGroupManager) initBackendGroupRegion() error
}
}
return nil
}
}*/
func (manager *SLoadbalancerBackendGroupManager) GetResourceCount() ([]db.SProjectResourceCount, error) {
virts := manager.Query().IsFalse("pending_deleted")

View File

@@ -145,6 +145,14 @@ func (man *SLoadbalancerBackendManager) ValidateBackendVpc(lb *SLoadbalancer, gu
return nil
}
func (man *SLoadbalancerBackendManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
backendGroupV := validators.NewModelIdOrNameValidator("backend_group", "loadbalancerbackendgroup", nil)
if err := backendGroupV.Validate(data.(*jsonutils.JSONDict)); err == nil {
return backendGroupV.Model.GetOwnerId(), nil
}
return man.SVirtualResourceBaseManager.FetchOwnerId(ctx, data)
}
func (man *SLoadbalancerBackendManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data *jsonutils.JSONDict) (*jsonutils.JSONDict, error) {
backendGroupV := validators.NewModelIdOrNameValidator("backend_group", "loadbalancerbackendgroup", ownerId)
if err := backendGroupV.Validate(data); err != nil {

View File

@@ -397,6 +397,14 @@ func (man *SLoadbalancerListenerRuleManager) ListItemFilter(ctx context.Context,
return q, nil
}
func (man *SLoadbalancerListenerRuleManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
listenerV := validators.NewModelIdOrNameValidator("listener", "loadbalancerlistener", nil)
if err := listenerV.Validate(data.(*jsonutils.JSONDict)); err == nil {
return listenerV.Model.GetOwnerId(), nil
}
return man.SVirtualResourceBaseManager.FetchOwnerId(ctx, data)
}
func (man *SLoadbalancerListenerRuleManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data *jsonutils.JSONDict) (*jsonutils.JSONDict, error) {
input := apis.VirtualResourceCreateInput{}
err := data.Unmarshal(&input)

View File

@@ -224,6 +224,14 @@ func (man *SLoadbalancerListenerManager) ListItemFilter(ctx context.Context, q *
return q, nil
}
func (man *SLoadbalancerListenerManager) FetchOwnerId(ctx context.Context, data jsonutils.JSONObject) (mcclient.IIdentityProvider, error) {
lbV := validators.NewModelIdOrNameValidator("loadbalancer", "loadbalancer", nil)
if err := lbV.Validate(data.(*jsonutils.JSONDict)); err == nil {
return lbV.Model.GetOwnerId(), nil
}
return man.SVirtualResourceBaseManager.FetchOwnerId(ctx, data)
}
func (man *SLoadbalancerListenerManager) ValidateCreateData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data *jsonutils.JSONDict) (*jsonutils.JSONDict, error) {
lbV := validators.NewModelIdOrNameValidator("loadbalancer", "loadbalancer", ownerId)
if err := lbV.Validate(data); err != nil {
@@ -345,7 +353,7 @@ func (lblis *SLoadbalancerListener) StartLoadBalancerListenerSyncstatusTask(ctx
func (lblis *SLoadbalancerListener) ValidateUpdateData(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data *jsonutils.JSONDict) (*jsonutils.JSONDict, error) {
ownerId := lblis.GetOwnerId()
backendGroupV := validators.NewModelIdOrNameValidator("backend_group", "loadbalancerbackendgroup", ownerId)
backendGroupV.AllowEmpty(true).Optional(true)
backendGroupV.AllowEmpty(true).Default(lblis.BackendGroupId)
if err := backendGroupV.Validate(data); err != nil {
return nil, err
}

View File

@@ -24,6 +24,7 @@ import (
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/compare"
"yunion.io/x/pkg/utils"
"yunion.io/x/sqlchemy"
"yunion.io/x/onecloud/pkg/apis"
@@ -318,7 +319,8 @@ func (lb *SLoadbalancer) GetCreateLoadbalancerParams(iRegion cloudprovider.IClou
if lb.ChargeType == api.LB_CHARGE_TYPE_BY_BANDWIDTH {
params.EgressMbps = lb.EgressMbps
}
if lb.AddressType == api.LB_ADDR_TYPE_INTRANET || lb.GetProviderName() == api.CLOUD_PROVIDER_HUAWEI || lb.GetProviderName() == api.CLOUD_PROVIDER_AWS {
if lb.AddressType == api.LB_ADDR_TYPE_INTRANET || utils.IsInStringArray(lb.SManagedResourceBase.GetProviderName(), []string{api.CLOUD_PROVIDER_HUAWEI, api.CLOUD_PROVIDER_AWS, api.CLOUD_PROVIDER_QCLOUD}) {
vpc := lb.GetVpc()
if vpc == nil {
return nil, fmt.Errorf("failed to find vpc for lb %s", lb.Name)
@@ -328,6 +330,9 @@ func (lb *SLoadbalancer) GetCreateLoadbalancerParams(iRegion cloudprovider.IClou
return nil, err
}
params.VpcID = iVpc.GetId()
}
if lb.AddressType == api.LB_ADDR_TYPE_INTRANET || utils.IsInStringArray(lb.SManagedResourceBase.GetProviderName(), []string{api.CLOUD_PROVIDER_HUAWEI, api.CLOUD_PROVIDER_AWS}) {
networks, err := lb.GetNetworks()
if err != nil {
return nil, fmt.Errorf("failed to find network for lb %s: %s", lb.Name, err)
@@ -775,11 +780,18 @@ func (lb *SLoadbalancer) SyncWithCloudLoadbalancer(ctx context.Context, userCred
lb.LoadbalancerSpec = extLb.GetLoadbalancerSpec()
lb.EgressMbps = extLb.GetEgressMbps()
lb.ChargeType = extLb.GetChargeType()
lbNetworkIds := getExtLbNetworkIds(extLb)
lb.NetworkId = strings.Join(lbNetworkIds, ",")
if extLb.GetMetadata() != nil {
lb.LBInfo = extLb.GetMetadata()
}
if vpcId := extLb.GetVpcId(); len(vpcId) > 0 {
if vpc, err := db.FetchByExternalId(VpcManager, vpcId); err == nil && vpc != nil {
lb.VpcId = vpc.GetId()
}
}
return nil
})

View File

@@ -50,10 +50,6 @@ import (
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
var (
ALL_NETWORK_TYPES = api.ALL_NETWORK_TYPES
)
type SNetworkManager struct {
db.SSharableVirtualResourceBaseManager
}
@@ -745,10 +741,11 @@ func (manager *SNetworkManager) GetOnPremiseNetworkOfIP(ipAddr string, serverTyp
}
q := manager.Query()
wires := WireManager.Query().SubQuery()
vpcs := VpcManager.Query().SubQuery()
// vpcs := VpcManager.Query().SubQuery()
q = q.Join(wires, sqlchemy.Equals(q.Field("wire_id"), wires.Field("id")))
q = q.Join(vpcs, sqlchemy.Equals(wires.Field("vpc_id"), vpcs.Field("id")))
q = q.Filter(sqlchemy.IsNullOrEmpty(vpcs.Field("manager_id")))
// q = q.Join(vpcs, sqlchemy.Equals(wires.Field("vpc_id"), vpcs.Field("id")))
// q = q.Filter(sqlchemy.IsNullOrEmpty(vpcs.Field("manager_id")))
q = q.Filter(sqlchemy.Equals(wires.Field("vpc_id"), api.DEFAULT_VPC_ID))
if len(serverType) > 0 {
q = q.Filter(sqlchemy.Equals(q.Field("server_type"), serverType))
}
@@ -1420,7 +1417,7 @@ func (manager *SNetworkManager) ValidateCreateData(ctx context.Context, userCred
if len(input.ServerType) == 0 {
input.ServerType = api.NETWORK_TYPE_GUEST
} else if !utils.IsInStringArray(input.ServerType, ALL_NETWORK_TYPES) {
} else if !utils.IsInStringArray(input.ServerType, api.ALL_NETWORK_TYPES) {
return input, httperrors.NewInputParameterError("Invalid server_type: %s", input.ServerType)
}

View File

@@ -116,6 +116,12 @@ type IRegionDriver interface {
RequestCacheSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, region *SCloudregion, vpc *SVpc, secgroup *SSecurityGroup, classic bool, task taskman.ITask) error
RequestSyncSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, vpcId string, vpc *SVpc, secgroup *SSecurityGroup) (string, error)
GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder // Desc(priority值越大,优先级越高) Asc(priority值越小,优先级越高)
GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule
GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule
GetSecurityGroupRuleMaxPriority() int
GetSecurityGroupRuleMinPriority() int
IsOnlySupportAllowRules() bool
IsSupportClassicSecurityGroup() bool
IsSecurityGroupBelongVpc() bool
IsVpcBelongGlobalVpc() bool

View File

@@ -32,6 +32,7 @@ import (
"yunion.io/x/onecloud/pkg/cloudprovider"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
type SSecurityGroupCacheManager struct {
@@ -104,6 +105,25 @@ func (self *SSecurityGroupCache) GetIRegion() (cloudprovider.ICloudRegion, error
return nil, fmt.Errorf("failed to find iregion for secgroupcache %s vpc: %s externalId: %s", self.Id, self.VpcId, self.ExternalId)
}
func (manager *SSecurityGroupCacheManager) FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
if userCred != nil {
sq := SecurityGroupManager.Query("id")
switch scope {
case rbacutils.ScopeProject:
if len(userCred.GetProjectId()) > 0 {
sq = sq.Equals("tenant_id", userCred.GetProjectId())
return q.In("secgroup_id", sq)
}
case rbacutils.ScopeDomain:
if len(userCred.GetProjectDomainId()) > 0 {
sq = sq.Equals("domain_id", userCred.GetProjectDomainId())
return q.In("secgroup_id", sq)
}
}
}
return q
}
func (self *SSecurityGroupCache) GetVpc() (*SVpc, error) {
vpc, err := VpcManager.FetchById(self.VpcId)
if err != nil {

View File

@@ -32,6 +32,7 @@ import (
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
"yunion.io/x/onecloud/pkg/cloudcommon/validators"
"yunion.io/x/onecloud/pkg/cloudprovider"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/logclient"
@@ -113,7 +114,7 @@ func (manager *SSecurityGroupRuleManager) FetchOwnerId(ctx context.Context, data
}
return secgroup.(*SSecurityGroup).GetOwnerId(), nil
}
return nil, nil
return db.FetchProjectInfo(ctx, data)
}
func (manager *SSecurityGroupRuleManager) FilterByOwner(q *sqlchemy.SQuery, userCred mcclient.IIdentityProvider, scope rbacutils.TRbacScope) *sqlchemy.SQuery {
@@ -335,13 +336,13 @@ func (manager *SSecurityGroupRuleManager) getRulesBySecurityGroup(secgroup *SSec
return rules, nil
}
func (manager *SSecurityGroupRuleManager) SyncRules(ctx context.Context, userCred mcclient.TokenCredential, secgroup *SSecurityGroup, rules secrules.SecurityRuleSet) compare.SyncResult {
func (manager *SSecurityGroupRuleManager) SyncRules(ctx context.Context, userCred mcclient.TokenCredential, secgroup *SSecurityGroup, rules cloudprovider.SecurityRuleSet) compare.SyncResult {
syncResult := compare.SyncResult{}
priority, prePriority := 100, 0
priority, prePriority := 10, 0
for i := 0; i < len(rules); i++ {
// 这里避免了Rule规则优先级在 1-100之外的问题,ext.GetRules()不需要进行优先级转换
if prePriority != 0 && rules[i].Priority != prePriority && priority > 1 {
priority--
if prePriority != 0 && rules[i].Priority != prePriority && priority < 100 {
priority++
}
prePriority = rules[i].Priority
rules[i].Priority = priority
@@ -355,7 +356,7 @@ func (manager *SSecurityGroupRuleManager) SyncRules(ctx context.Context, userCre
return syncResult
}
func (manager *SSecurityGroupRuleManager) newFromCloudSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, rule secrules.SecurityRule, secgroup *SSecurityGroup) (*SSecurityGroupRule, error) {
func (manager *SSecurityGroupRuleManager) newFromCloudSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, rule cloudprovider.SecurityRule, secgroup *SSecurityGroup) (*SSecurityGroupRule, error) {
lockman.LockClass(ctx, manager, db.GetLockClassKey(manager, userCred))
defer lockman.ReleaseClass(ctx, manager, db.GetLockClassKey(manager, userCred))

View File

@@ -17,7 +17,6 @@ package models
import (
"context"
"database/sql"
"sort"
"strings"
"time"
@@ -645,44 +644,46 @@ func (manager *SSecurityGroupManager) getSecurityGroups() ([]SSecurityGroup, err
}
func (manager *SSecurityGroupManager) newFromCloudSecgroup(ctx context.Context, userCred mcclient.TokenCredential, provider *SCloudprovider, extSec cloudprovider.ICloudSecurityGroup) (*SSecurityGroup, error) {
regionDriver, err := provider.GetRegionDriver()
if err != nil {
return nil, errors.Wrap(err, "provider.GetRegionDriver")
}
rules, err := extSec.GetRules()
if err != nil {
return nil, err
return nil, errors.Wrap(err, "extSec.GetRules")
}
inRules := secrules.SecurityRuleSet{}
outRules := secrules.SecurityRuleSet{}
for i := 0; i < len(rules); i++ {
inRules := []cloudprovider.SecurityRule{}
outRules := []cloudprovider.SecurityRule{}
for i := range rules {
if rules[i].Direction == secrules.DIR_IN {
inRules = append(inRules, rules[i])
} else {
outRules = append(outRules, rules[i])
}
}
sort.Sort(inRules)
sort.Sort(outRules)
inAllowList := inRules.AllowList()
outAllowList := outRules.AllowList()
maxPriority := regionDriver.GetSecurityGroupRuleMaxPriority()
minPriority := regionDriver.GetSecurityGroupRuleMinPriority()
defaultInRule := regionDriver.GetDefaultSecurityGroupInRule()
defaultOutRule := regionDriver.GetDefaultSecurityGroupOutRule()
order := regionDriver.GetSecurityGroupRuleOrder()
onlyAllowRules := regionDriver.IsOnlySupportAllowRules()
// 查询所有共享或与provider在同一项目的安全组比对寻找一个与云上安全组规则相同的安全组
secgroups := []SSecurityGroup{}
q := manager.Query()
q = q.Filter(
sqlchemy.OR(
sqlchemy.Equals(q.Field("tenant_id"), provider.ProjectId),
sqlchemy.AND(
sqlchemy.IsTrue(q.Field("is_public")),
sqlchemy.Equals(q.Field("public_scope"), rbacutils.ScopeSystem),
),
),
)
if err := db.FetchModelObjects(manager, q, &secgroups); err != nil {
log.Errorf("failed to fetch secgroups %v", err)
q := manager.Query().Equals("domain_id", provider.DomainId)
err = db.FetchModelObjects(manager, q, &secgroups)
if err != nil {
return nil, errors.Wrap(err, "db.FetchModelObjects")
}
for _, secgroup := range secgroups {
_inAllowList := secgroup.GetInAllowList()
_outAllowList := secgroup.GetOutAllowList()
if outAllowList.Equals(_outAllowList) && inAllowList.Equals(_inAllowList) {
return &secgroup, nil
for i := range secgroups {
localRules := secrules.SecurityRuleSet(secgroups[i].GetSecRules(""))
_, inAdds, outAdds, inDels, outDels := cloudprovider.CompareRules(minPriority, maxPriority, order, localRules, rules, defaultInRule, defaultOutRule, onlyAllowRules, false)
if len(inAdds) == 0 && len(outAdds) == 0 && len(inDels) == 0 && len(outDels) == 0 {
return &secgroups[i], nil
}
}
@@ -695,6 +696,7 @@ func (manager *SSecurityGroupManager) newFromCloudSecgroup(ctx context.Context,
if err != nil {
return nil, err
}
secgroup.Name = newName
secgroup.Description = extSec.GetDescription()
secgroup.ProjectId = provider.ProjectId
@@ -705,6 +707,11 @@ func (manager *SSecurityGroupManager) newFromCloudSecgroup(ctx context.Context,
}
//这里必须先同步下规则,不然下次对比此安全组规则为空
inRules = cloudprovider.AddDefaultRule(inRules, defaultInRule, "in:deny any", order, minPriority, maxPriority, onlyAllowRules)
cloudprovider.SortSecurityRule(inRules, order, onlyAllowRules)
outRules = cloudprovider.AddDefaultRule(outRules, defaultOutRule, "out:allow any", order, minPriority, maxPriority, onlyAllowRules)
cloudprovider.SortSecurityRule(outRules, order, onlyAllowRules)
SecurityGroupRuleManager.SyncRules(ctx, userCred, &secgroup, inRules)
SecurityGroupRuleManager.SyncRules(ctx, userCred, &secgroup, outRules)
@@ -719,18 +726,21 @@ func (manager *SSecurityGroupManager) DelaySync(ctx context.Context, userCred mc
} else {
needSync := false
lockman.LockObject(ctx, secgrp)
defer lockman.ReleaseObject(ctx, secgrp)
func() {
lockman.LockObject(ctx, secgrp)
defer lockman.ReleaseObject(ctx, secgrp)
if secgrp.IsDirty {
if _, err := db.Update(secgrp, func() error {
secgrp.IsDirty = false
return nil
}); err != nil {
log.Errorf("Update Security Group error: %s", err.Error())
if secgrp.IsDirty {
if _, err := db.Update(secgrp, func() error {
secgrp.IsDirty = false
return nil
}); err != nil {
log.Errorf("Update Security Group error: %s", err.Error())
}
needSync = true
}
needSync = true
}
}()
if needSync {
for _, guest := range secgrp.GetGuests() {
guest.StartSyncTask(ctx, userCred, true, "")
@@ -747,7 +757,7 @@ func (self *SSecurityGroup) DoSync(ctx context.Context, userCred mcclient.TokenC
log.Errorf("Update Security Group error: %s", err.Error())
}
time.AfterFunc(10*time.Second, func() {
SecurityGroupManager.DelaySync(ctx, userCred, self.Id)
SecurityGroupManager.DelaySync(context.Background(), userCred, self.Id)
})
}

View File

@@ -384,9 +384,8 @@ func (self *SSnapshotManager) GetDiskSnapshotsByCreate(diskId, createdBy string)
func (self *SSnapshotManager) GetDiskSnapshots(diskId string) []SSnapshot {
dest := make([]SSnapshot, 0)
q := self.Query().SubQuery()
sq := q.Query().Filter(sqlchemy.AND(sqlchemy.Equals(q.Field("disk_id"), diskId)))
err := db.FetchModelObjects(self, sq, &dest)
q := self.Query().Equals("disk_id", diskId).Asc("created_at")
err := db.FetchModelObjects(self, q, &dest)
if err != nil {
log.Errorf("GetDiskSnapshots error: %s", err)
return nil

View File

@@ -108,11 +108,10 @@ func (manager *SWireManager) ValidateCreateData(ctx context.Context, userCred mc
}
vpcStr := jsonutils.GetAnyString(data, []string{"vpc", "vpc_id"})
if len(vpcStr) == 0 {
return nil, httperrors.NewMissingParameterError("vpc_id")
if vpcStr == "" {
vpcStr = api.DEFAULT_VPC_ID
}
if len(vpcStr) > 0 {
{
vpcObj, err := VpcManager.FetchByIdOrName(userCred, vpcStr)
if err != nil {
if err == sql.ErrNoRows {

View File

@@ -116,7 +116,7 @@ type ComputeOptions struct {
SyncPurgeRemovedResources []string `help:"resources that shoud be purged immediately if found removed"`
DisconnectedCloudAccountRetryProbeIntervalHours int `help:"interval to wait to probe status of a disconnected cloud account" default:"24"`
DisconnectedCloudAccountRetryProbeIntervalHours int `help:"interval to wait to probe status of a disconnected cloud account" default:"2"`
BaremetalServerReuseHostIp bool `help:"baremetal server reuse host IP address, default true" default:"true"`

View File

@@ -25,6 +25,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/pkg/utils"
billing_api "yunion.io/x/onecloud/pkg/apis/billing"
@@ -52,6 +53,26 @@ func init() {
models.RegisterRegionDriver(&driver)
}
func (self *SAliyunRegionDriver) GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder {
return cloudprovider.PriorityOrderByAsc
}
func (self *SAliyunRegionDriver) GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("in:deny any")}
}
func (self *SAliyunRegionDriver) GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("out:allow any")}
}
func (self *SAliyunRegionDriver) GetSecurityGroupRuleMaxPriority() int {
return 1
}
func (self *SAliyunRegionDriver) GetSecurityGroupRuleMinPriority() int {
return 100
}
func (self *SAliyunRegionDriver) GetProvider() string {
return api.CLOUD_PROVIDER_ALIYUN
}

View File

@@ -24,6 +24,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/pkg/utils"
"yunion.io/x/sqlchemy"
@@ -38,6 +39,7 @@ import (
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/onecloud/pkg/util/choices"
"yunion.io/x/onecloud/pkg/util/rand"
"yunion.io/x/onecloud/pkg/util/rbacutils"
)
type SAwsRegionDriver struct {
@@ -49,10 +51,48 @@ func init() {
models.RegisterRegionDriver(&driver)
}
func (self *SAwsRegionDriver) GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder {
return cloudprovider.PriorityOrderByAsc
}
func (self *SAwsRegionDriver) GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("in:deny any")}
}
func (self *SAwsRegionDriver) GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("out:allow any")}
}
func (self *SAwsRegionDriver) GetSecurityGroupRuleMaxPriority() int {
return 0
}
func (self *SAwsRegionDriver) GetSecurityGroupRuleMinPriority() int {
return 0
}
func (self *SAwsRegionDriver) IsOnlySupportAllowRules() bool {
return true
}
func (self *SAwsRegionDriver) GetProvider() string {
return api.CLOUD_PROVIDER_AWS
}
func networkCheck(network *models.SNetwork) error {
total := network.GetPorts()
used, err := network.GetTotalNicCount()
if err != nil {
return errors.Wrap(err, "validateAwsLbNetwork.GetTotalNicCount")
}
if (total - used) < 8 {
return fmt.Errorf("network %s free ip is less than 8", network.GetId())
}
return nil
}
func validateAwsLbNetwork(ownerId mcclient.IIdentityProvider, data *jsonutils.JSONDict, requiredMin int) (*jsonutils.JSONDict, error) {
var networkIds []string
if ns, err := data.GetString("network"); err != nil {
@@ -74,21 +114,45 @@ func validateAwsLbNetwork(ownerId mcclient.IIdentityProvider, data *jsonutils.JS
}
network := networkV.Model.(*models.SNetwork)
err := networkCheck(network)
if err != nil {
return nil, errors.Wrap(err, "validateAwsLbNetwork.networkCheck")
}
region, zone, vpc, _, err := network.ValidateElbNetwork(nil)
if err != nil {
return nil, err
} else {
//随机选择一个子网
if requiredMin == 2 && len(networkIds) == 1 {
var nets []models.SNetwork
wires := models.WireManager.Query().SubQuery()
q := models.NetworkManager.Query().IsFalse("pending_deleted")
q = models.NetworkManager.FilterByOwner(q, ownerId, rbacutils.ScopeProject)
q = q.Join(wires, sqlchemy.Equals(q.Field("wire_id"), wires.Field("id")))
q = q.Filter(sqlchemy.Equals(wires.Field("vpc_id"), vpc.GetId()))
q = q.Filter(sqlchemy.NotEquals(wires.Field("zone_id"), zone.GetId()))
err := q.First(secondNet)
err := q.All(&nets)
if err != nil {
return nil, httperrors.NewInputParameterError("required at least %d subnet.", requiredMin)
}
secondNetFound := false
for i := range nets {
net := nets[i]
err := networkCheck(&net)
if err != nil {
continue
}
secondNet = &net
secondNetFound = true
break
}
if !secondNetFound {
return nil, httperrors.NewInputParameterError("required at least %d subnet with at least 8 free ip.", requiredMin)
}
}
}
@@ -881,7 +945,7 @@ func (self *SAwsRegionDriver) RequestCreateLoadbalancerBackend(ctx context.Conte
}
if ibackend != nil {
if err := lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, ibackend, nil); err != nil {
if err := lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, ibackend, lbbg.GetOwnerId()); err != nil {
return nil, errors.Wrap(err, "AwsRegionDriver.RequestCreateLoadbalancerBackend.SyncWithCloudLoadbalancerBackend")
}
}
@@ -1094,7 +1158,7 @@ func (self *SAwsRegionDriver) RequestCreateLoadbalancerListenerRule(ctx context.
if err := db.SetExternalId(lbr, userCred, iListenerRule.GetGlobalId()); err != nil {
return nil, err
}
return nil, lbr.SyncWithCloudLoadbalancerListenerRule(ctx, userCred, iListenerRule, nil)
return nil, lbr.SyncWithCloudLoadbalancerListenerRule(ctx, userCred, iListenerRule, listener.GetOwnerId())
})
return nil
}
@@ -1322,7 +1386,7 @@ func (self *SAwsRegionDriver) RequestSyncLoadbalancerListener(ctx context.Contex
if err := iListener.Refresh(); err != nil {
return nil, errors.Wrap(err, "awsRegionDriver.RequestSyncLoadbalancerListener.Refresh")
}
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, nil)
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, loadbalancer.GetOwnerId())
})
return nil
}

View File

@@ -18,8 +18,10 @@ import (
"context"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/util/secrules"
api "yunion.io/x/onecloud/pkg/apis/compute"
"yunion.io/x/onecloud/pkg/cloudprovider"
"yunion.io/x/onecloud/pkg/compute/models"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
@@ -53,3 +55,23 @@ func (self *SAzureRegionDriver) ValidateCreateLoadbalancerCertificateData(ctx co
func (self *SAzureRegionDriver) IsSupportClassicSecurityGroup() bool {
return true
}
func (self *SAzureRegionDriver) GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder {
return cloudprovider.PriorityOrderByAsc
}
func (self *SAzureRegionDriver) GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("in:deny any")}
}
func (self *SAzureRegionDriver) GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("out:deny any")}
}
func (self *SAzureRegionDriver) GetSecurityGroupRuleMaxPriority() int {
return 4096
}
func (self *SAzureRegionDriver) GetSecurityGroupRuleMinPriority() int {
return 100
}

View File

@@ -20,6 +20,7 @@ import (
"time"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/util/secrules"
api "yunion.io/x/onecloud/pkg/apis/compute"
"yunion.io/x/onecloud/pkg/cloudcommon/db/taskman"
@@ -235,6 +236,30 @@ func (self *SBaseRegionDriver) RequestSyncSecurityGroup(ctx context.Context, use
return "", fmt.Errorf("Not Implemented RequestSyncSecurityGroup")
}
func (self *SBaseRegionDriver) GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder {
return cloudprovider.PriorityOrderByDesc
}
func (self *SBaseRegionDriver) IsOnlySupportAllowRules() bool {
return false
}
func (self *SBaseRegionDriver) GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("in:deny any")}
}
func (self *SBaseRegionDriver) GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("out:allow any")}
}
func (self *SBaseRegionDriver) GetSecurityGroupRuleMaxPriority() int {
return 100
}
func (self *SBaseRegionDriver) GetSecurityGroupRuleMinPriority() int {
return 1
}
func (self *SBaseRegionDriver) ValidateCreateDBInstanceData(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, input *api.SDBInstanceCreateInput, skus []models.SDBInstanceSku, network *models.SNetwork) (*api.SDBInstanceCreateInput, error) {
return input, nil
}

View File

@@ -18,8 +18,10 @@ import (
"context"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/util/secrules"
api "yunion.io/x/onecloud/pkg/apis/compute"
"yunion.io/x/onecloud/pkg/cloudprovider"
"yunion.io/x/onecloud/pkg/compute/models"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
@@ -34,6 +36,30 @@ func init() {
models.RegisterRegionDriver(&driver)
}
func (self *SCtyunRegionDriver) GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder {
return cloudprovider.PriorityOrderByAsc
}
func (self *SCtyunRegionDriver) GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("in:deny any")}
}
func (self *SCtyunRegionDriver) GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("out:deny any")}
}
func (self *SCtyunRegionDriver) GetSecurityGroupRuleMaxPriority() int {
return 0
}
func (self *SCtyunRegionDriver) GetSecurityGroupRuleMinPriority() int {
return 0
}
func (self *SCtyunRegionDriver) IsOnlySupportAllowRules() bool {
return true
}
func (self *SCtyunRegionDriver) GetProvider() string {
return api.CLOUD_PROVIDER_CTYUN
}

View File

@@ -15,7 +15,10 @@
package regiondrivers
import (
"yunion.io/x/pkg/util/secrules"
api "yunion.io/x/onecloud/pkg/apis/compute"
"yunion.io/x/onecloud/pkg/cloudprovider"
"yunion.io/x/onecloud/pkg/compute/models"
)
@@ -28,6 +31,26 @@ func init() {
models.RegisterRegionDriver(&driver)
}
func (self *SGoogleRegionDriver) GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder {
return cloudprovider.PriorityOrderByAsc
}
func (self *SGoogleRegionDriver) GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("in:deny any")}
}
func (self *SGoogleRegionDriver) GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("out:allow any")}
}
func (self *SGoogleRegionDriver) GetSecurityGroupRuleMaxPriority() int {
return 0
}
func (self *SGoogleRegionDriver) GetSecurityGroupRuleMinPriority() int {
return 65535
}
func (self *SGoogleRegionDriver) GetProvider() string {
return api.CLOUD_PROVIDER_GOOGLE
}

View File

@@ -25,6 +25,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/pkg/utils"
billing_api "yunion.io/x/onecloud/pkg/apis/billing"
@@ -52,6 +53,30 @@ func init() {
models.RegisterRegionDriver(&driver)
}
func (self *SHuaWeiRegionDriver) GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder {
return cloudprovider.PriorityOrderByAsc
}
func (self *SHuaWeiRegionDriver) GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("in:deny any")}
}
func (self *SHuaWeiRegionDriver) GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("out:allow any")}
}
func (self *SHuaWeiRegionDriver) GetSecurityGroupRuleMaxPriority() int {
return 0
}
func (self *SHuaWeiRegionDriver) GetSecurityGroupRuleMinPriority() int {
return 0
}
func (self *SHuaWeiRegionDriver) IsOnlySupportAllowRules() bool {
return true
}
func (self *SHuaWeiRegionDriver) GetProvider() string {
return api.CLOUD_PROVIDER_HUAWEI
}
@@ -1851,20 +1876,20 @@ func (self *SHuaWeiRegionDriver) RequestCreateLoadbalancer(ctx context.Context,
taskman.LocalTaskRun(task, func() (jsonutils.JSONObject, error) {
iRegion, err := lb.GetIRegion()
if err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.GetIRegion")
}
params, err := lb.GetCreateLoadbalancerParams(iRegion)
if err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.GetCreateLoadbalancerParams")
}
iLoadbalancer, err := iRegion.CreateILoadBalancer(params)
if err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.CreateILoadBalancer")
}
lb.SetModelManager(models.LoadbalancerManager, lb)
if err := db.SetExternalId(lb, userCred, iLoadbalancer.GetGlobalId()); err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.SetExternalId")
}
{
@@ -1873,7 +1898,7 @@ func (self *SHuaWeiRegionDriver) RequestCreateLoadbalancer(ctx context.Context,
if len(eipId) > 0 {
ieip, err := iRegion.GetIEipById(eipId)
if err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.GetIEipById")
}
conf := &cloudprovider.AssociateConfig{
@@ -1883,27 +1908,27 @@ func (self *SHuaWeiRegionDriver) RequestCreateLoadbalancer(ctx context.Context,
err = ieip.Associate(conf)
if err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.Associate")
}
eip, err := db.FetchByExternalId(models.ElasticipManager, ieip.GetGlobalId())
if err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.FetchByExternalId")
}
err = eip.(*models.SElasticip).SyncWithCloudEip(ctx, userCred, lb.GetCloudprovider(), ieip, lb.GetOwnerId())
if err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.SyncWithCloudEip")
}
}
}
if err := lb.SyncWithCloudLoadbalancer(ctx, userCred, iLoadbalancer, nil); err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.SyncWithCloudLoadbalancer")
}
lbbgs, err := iLoadbalancer.GetILoadBalancerBackendGroups()
if err != nil {
return nil, err
return nil, errors.Wrap(err, "Huawei.RequestCreateLoadbalancer.GetILoadBalancerBackendGroups")
}
if len(lbbgs) > 0 {
provider := lb.GetCloudprovider()
@@ -1982,7 +2007,7 @@ func (self *SHuaWeiRegionDriver) RequestSyncLoadbalancerBackend(ctx context.Cont
return nil, errors.Wrap(err, "huaweiRegionDriver.RequestSyncLoadbalancerBackend.GetILoadbalancerBackendById")
}
err = cachedlbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, iBackend, nil)
err = cachedlbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, iBackend, lbb.GetOwnerId())
if err != nil {
return nil, errors.Wrap(err, "huaweiRegionDriver.RequestSyncLoadbalancerBackend.SyncWithCloudLoadbalancerBackend")
}
@@ -2041,7 +2066,7 @@ func (self *SHuaWeiRegionDriver) RequestCreateLoadbalancerBackend(ctx context.Co
}
if ibackend != nil {
if err := lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, ibackend, nil); err != nil {
if err := lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, ibackend, lbbg.GetOwnerId()); err != nil {
return nil, errors.Wrap(err, "huaweiRegionDriver.RequestCreateLoadbalancerBackend.SyncWithCloudLoadbalancerBackend")
}
}
@@ -2104,7 +2129,7 @@ func (self *SHuaWeiRegionDriver) RequestCreateLoadbalancerListenerRule(ctx conte
if err := db.SetExternalId(lbr, userCred, iListenerRule.GetGlobalId()); err != nil {
return nil, errors.Wrap(err, "huaweiRegionDriver.RequestCreateLoadbalancerListenerRule.SetExternalId")
}
return nil, lbr.SyncWithCloudLoadbalancerListenerRule(ctx, userCred, iListenerRule, nil)
return nil, lbr.SyncWithCloudLoadbalancerListenerRule(ctx, userCred, iListenerRule, listener.GetOwnerId())
})
return nil
}

View File

@@ -18,7 +18,6 @@ import (
"context"
"database/sql"
"fmt"
"sort"
"strings"
"time"
@@ -595,7 +594,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestCreateLoadbalancerBackend
if err := db.SetExternalId(lbb, userCred, iLoadbalancerBackend.GetGlobalId()); err != nil {
return nil, err
}
return nil, lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, iLoadbalancerBackend, nil)
return nil, lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, iLoadbalancerBackend, lbbg.GetOwnerId())
})
return nil
}
@@ -680,7 +679,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestSyncLoadbalancerBackend(c
return nil, errors.Wrap(err, "regionDriver.RequestSyncLoadbalancerBackend.GetILoadbalancerBackendById")
}
return nil, lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, iBackend, nil)
return nil, lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, iBackend, lbbg.GetOwnerId())
})
return nil
}
@@ -780,7 +779,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestCreateLoadbalancerListene
if err := db.SetExternalId(lblis, userCred, iListener.GetGlobalId()); err != nil {
return nil, errors.Wrap(err, "db.SetExternalId")
}
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, nil)
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, loadbalancer.GetOwnerId())
})
return nil
}
@@ -951,7 +950,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestSyncLoadbalancerListener(
if err := iListener.Refresh(); err != nil {
return nil, errors.Wrap(err, "regionDriver.RequestSyncLoadbalancerListener.RefreshListener")
}
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, nil)
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, loadbalancer.GetOwnerId())
})
return nil
}
@@ -1048,7 +1047,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestCreateLoadbalancerListene
if err := db.SetExternalId(lbr, userCred, iListenerRule.GetGlobalId()); err != nil {
return nil, err
}
return nil, lbr.SyncWithCloudLoadbalancerListenerRule(ctx, userCred, iListenerRule, nil)
return nil, lbr.SyncWithCloudLoadbalancerListenerRule(ctx, userCred, iListenerRule, listener.GetOwnerId())
})
return nil
}
@@ -1432,8 +1431,11 @@ func (self *SManagedVirtualizationRegionDriver) RequestSyncSecurityGroup(ctx con
secgroup.Name = "DefaultGroup"
}
// 避免有的云不支持重名安全组
groupName := secgroup.Name
for i := 0; i < 30; i++ {
randomString := func(prefix string, length int) string {
return fmt.Sprintf("%s-%s", prefix, rand.String(length))
}
groupName := randomString(secgroup.Name, 1)
for i := 2; i < 30; i++ {
_, err := iRegion.GetISecurityGroupByName(vpc.ExternalId, groupName)
if err != nil {
if errors.Cause(err) == cloudprovider.ErrNotFound {
@@ -1443,7 +1445,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestSyncSecurityGroup(ctx con
return "", err
}
}
groupName = fmt.Sprintf("%s-%d", secgroup.Name, i)
groupName = randomString(secgroup.Name, i)
}
conf := &cloudprovider.SecurityGroupCreateInput{
Name: groupName,
@@ -1468,35 +1470,32 @@ func (self *SManagedVirtualizationRegionDriver) RequestSyncSecurityGroup(ctx con
return "", errors.Wrap(err, "db.Update")
}
inAllowList := secgroup.GetInAllowList()
outAllowList := secgroup.GetOutAllowList()
rules, err := iSecgroup.GetRules()
if err != nil {
return "", errors.Wrap(err, "iSecgroup.GetRules")
}
inRules := secrules.SecurityRuleSet{}
outRules := secrules.SecurityRuleSet{}
for i := 0; i < len(rules); i++ {
if rules[i].Direction == secrules.DIR_IN {
inRules = append(inRules, rules[i])
} else {
outRules = append(outRules, rules[i])
}
}
sort.Sort(inRules)
sort.Sort(outRules)
_inAllowList := inRules.AllowList()
_outAllowList := outRules.AllowList()
if inAllowList.Equals(_inAllowList) && outAllowList.Equals(_outAllowList) {
maxPriority := region.GetDriver().GetSecurityGroupRuleMaxPriority()
minPriority := region.GetDriver().GetSecurityGroupRuleMinPriority()
defaultInRule := region.GetDriver().GetDefaultSecurityGroupInRule()
defaultOutRule := region.GetDriver().GetDefaultSecurityGroupOutRule()
order := region.GetDriver().GetSecurityGroupRuleOrder()
onlyAllowRules := region.GetDriver().IsOnlySupportAllowRules()
localRules := secrules.SecurityRuleSet(secgroup.GetSecRules(""))
common, inAdds, outAdds, inDels, outDels := cloudprovider.CompareRules(minPriority, maxPriority, order, localRules, rules, defaultInRule, defaultOutRule, onlyAllowRules, false)
if len(inAdds) == 0 && len(inDels) == 0 && len(outAdds) == 0 && len(outDels) == 0 {
return cache.ExternalId, nil
}
err = iSecgroup.SyncRules(secgroup.GetSecRules(""))
err = iSecgroup.SyncRules(common, inAdds, outAdds, inDels, outDels)
if err != nil {
return "", errors.Wrap(err, "iSecgroup.SyncRules")
}
return cache.ExternalId, nil
}

View File

@@ -18,9 +18,11 @@ import (
"context"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/util/secrules"
api "yunion.io/x/onecloud/pkg/apis/compute"
"yunion.io/x/onecloud/pkg/cloudcommon/validators"
"yunion.io/x/onecloud/pkg/cloudprovider"
"yunion.io/x/onecloud/pkg/compute/models"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
@@ -35,6 +37,30 @@ func init() {
models.RegisterRegionDriver(&driver)
}
func (self *SOpenStackRegionDriver) GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder {
return cloudprovider.PriorityOrderByDesc
}
func (self *SOpenStackRegionDriver) GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("in:deny any")}
}
func (self *SOpenStackRegionDriver) GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("out:deny any")}
}
func (self *SOpenStackRegionDriver) GetSecurityGroupRuleMaxPriority() int {
return 0
}
func (self *SOpenStackRegionDriver) GetSecurityGroupRuleMinPriority() int {
return 0
}
func (self *SOpenStackRegionDriver) IsOnlySupportAllowRules() bool {
return true
}
func (self *SOpenStackRegionDriver) GetProvider() string {
return api.CLOUD_PROVIDER_OPENSTACK
}

View File

@@ -22,6 +22,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/log"
"yunion.io/x/pkg/errors"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/pkg/utils"
"yunion.io/x/sqlchemy"
@@ -45,6 +46,26 @@ func init() {
models.RegisterRegionDriver(&driver)
}
func (self *SQcloudRegionDriver) GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder {
return cloudprovider.PriorityOrderByAsc
}
func (self *SQcloudRegionDriver) GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("in:deny any")}
}
func (self *SQcloudRegionDriver) GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule {
return cloudprovider.SecurityRule{SecurityRule: *secrules.MustParseSecurityRule("out:deny any")}
}
func (self *SQcloudRegionDriver) GetSecurityGroupRuleMaxPriority() int {
return 0
}
func (self *SQcloudRegionDriver) GetSecurityGroupRuleMinPriority() int {
return 100
}
func (self *SQcloudRegionDriver) GetProvider() string {
return api.CLOUD_PROVIDER_QCLOUD
}
@@ -305,7 +326,7 @@ func (self *SQcloudRegionDriver) RequestCreateLoadbalancerBackend(ctx context.Co
}
if ibackend != nil {
if err := lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, ibackend, nil); err != nil {
if err := lbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, ibackend, lbbg.GetOwnerId()); err != nil {
return nil, errors.Wrap(err, "qcloudRegionDriver.RequestCreateLoadbalancerBackend.SyncWithCloudLoadbalancerBackend")
}
}
@@ -592,7 +613,7 @@ func (self *SQcloudRegionDriver) RequestCreateLoadbalancerListener(ctx context.C
}
}
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, nil)
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, loadbalancer.GetOwnerId())
})
return nil
}
@@ -686,7 +707,7 @@ func (self *SQcloudRegionDriver) RequestCreateLoadbalancerListenerRule(ctx conte
return nil, errors.Wrap(err, "SQcloudRegionDriver.RequestCreateLoadbalancerListener.createLoadbalancerBackendGroup")
}
return nil, lbr.SyncWithCloudLoadbalancerListenerRule(ctx, userCred, iListenerRule, nil)
return nil, lbr.SyncWithCloudLoadbalancerListenerRule(ctx, userCred, iListenerRule, listener.GetOwnerId())
})
return nil
}
@@ -754,7 +775,7 @@ func (self *SQcloudRegionDriver) ValidateUpdateLoadbalancerListenerData(ctx cont
return nil, httperrors.NewInputParameterError("backend group %s(%s) belongs to loadbalancer %s instead of %s",
lbbg.Name, lbbg.Id, lbbg.LoadbalancerId, lblis.LoadbalancerId)
} else {
if utils.IsInStringArray(lblis.ListenerType, []string{api.LB_LISTENER_TYPE_TCP, api.LB_LISTENER_TYPE_UDP}) {
if lbbg != nil && utils.IsInStringArray(lblis.ListenerType, []string{api.LB_LISTENER_TYPE_TCP, api.LB_LISTENER_TYPE_UDP}) {
cachedLbbgs, err := lbbg.GetQcloudCachedlbbg()
if err != nil {
return nil, err
@@ -1106,7 +1127,7 @@ func (self *SQcloudRegionDriver) RequestSyncLoadbalancerBackend(ctx context.Cont
return nil, errors.Wrap(err, "qcloudRegionDriver.RequestSyncLoadbalancerBackend.Refresh")
}
err = cachedlbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, iBackend, nil)
err = cachedlbb.SyncWithCloudLoadbalancerBackend(ctx, userCred, iBackend, lbb.GetOwnerId())
if err != nil {
return nil, errors.Wrap(err, "qcloudRegionDriver.RequestSyncLoadbalancerBackend.SyncWithCloudLoadbalancerBackend")
}
@@ -1332,7 +1353,7 @@ func (self *SQcloudRegionDriver) RequestSyncLoadbalancerListener(ctx context.Con
}
if utils.IsInStringArray(lblis.ListenerType, []string{api.LB_LISTENER_TYPE_UDP, api.LB_LISTENER_TYPE_TCP}) {
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, nil)
return nil, lblis.SyncWithCloudLoadbalancerListener(ctx, userCred, loadbalancer, iListener, loadbalancer.GetOwnerId())
} else {
// http&https listener 变更不会同步到监听规则
return nil, nil

View File

@@ -0,0 +1,63 @@
// Copyright 2019 Yunion
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package regiondrivers
import (
"testing"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/onecloud/pkg/cloudprovider"
)
func TestAwsRuleSync(t *testing.T) {
driver := SAwsRegionDriver{}
maxPriority := driver.GetSecurityGroupRuleMaxPriority()
minPriority := driver.GetSecurityGroupRuleMinPriority()
defaultInRule := driver.GetDefaultSecurityGroupInRule()
defaultOutRule := driver.GetDefaultSecurityGroupOutRule()
order := driver.GetSecurityGroupRuleOrder()
isOnlyAllowRules := driver.IsOnlySupportAllowRules()
data := []TestData{
{
Name: "Test out deny rules",
LocalRules: secrules.SecurityRuleSet{
localRuleWithPriority("out:deny any", 1),
},
RemoteRules: []cloudprovider.SecurityRule{
remoteRuleWithName("", "out:allow any", 1),
},
Common: []cloudprovider.SecurityRule{},
InAdds: []cloudprovider.SecurityRule{},
OutAdds: []cloudprovider.SecurityRule{},
InDels: []cloudprovider.SecurityRule{},
OutDels: []cloudprovider.SecurityRule{
remoteRuleWithName("", "out:allow any", 1),
},
},
}
for _, d := range data {
t.Logf("check %s", d.Name)
common, inAdds, outAdds, inDels, outDels := cloudprovider.CompareRules(minPriority, maxPriority, order, d.LocalRules, d.RemoteRules, defaultInRule, defaultOutRule, isOnlyAllowRules, true)
check(t, "common", common, d.Common)
check(t, "inAdds", inAdds, d.InAdds)
check(t, "outAdds", outAdds, d.OutAdds)
check(t, "inDels", inDels, d.InDels)
check(t, "outDels", outDels, d.OutDels)
}
}

View File

@@ -0,0 +1,235 @@
// Copyright 2019 Yunion
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package regiondrivers
import (
"sort"
"testing"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/onecloud/pkg/cloudprovider"
)
func TestAzureRuleSync(t *testing.T) {
driver := SAzureRegionDriver{}
maxPriority := driver.GetSecurityGroupRuleMaxPriority()
minPriority := driver.GetSecurityGroupRuleMinPriority()
defaultInRule := driver.GetDefaultSecurityGroupInRule()
defaultOutRule := driver.GetDefaultSecurityGroupOutRule()
order := driver.GetSecurityGroupRuleOrder()
isOnlyAllowRules := driver.IsOnlySupportAllowRules()
data := []TestData{
{
Name: "Test empty rules",
LocalRules: secrules.SecurityRuleSet{},
RemoteRules: []cloudprovider.SecurityRule{},
Common: []cloudprovider.SecurityRule{},
InAdds: []cloudprovider.SecurityRule{},
OutAdds: []cloudprovider.SecurityRule{
remoteRuleWithName("", "out:allow any", 2097),
},
InDels: []cloudprovider.SecurityRule{},
OutDels: []cloudprovider.SecurityRule{},
},
{
Name: "Test remove rules",
LocalRules: secrules.SecurityRuleSet{},
RemoteRules: []cloudprovider.SecurityRule{
remoteRuleWithName("test-name", "out:allow any", 1000),
},
Common: []cloudprovider.SecurityRule{},
InAdds: []cloudprovider.SecurityRule{},
OutAdds: []cloudprovider.SecurityRule{
remoteRuleWithName("", "out:allow any", 2097),
},
InDels: []cloudprovider.SecurityRule{},
OutDels: []cloudprovider.SecurityRule{
remoteRuleWithName("test-name", "out:allow any", 1000),
},
},
{
Name: "Test diff rules",
LocalRules: secrules.SecurityRuleSet{
localRuleWithPriority("out:allow tcp 100-200", 99),
localRuleWithPriority("out:allow udp 200-300", 98),
},
RemoteRules: []cloudprovider.SecurityRule{
remoteRuleWithName("test-tcp", "out:allow tcp 100-200", 1000),
remoteRuleWithName("test-udp", "out:allow udp 200-300", 1002),
},
Common: []cloudprovider.SecurityRule{
remoteRuleWithName("test-tcp", "out:allow tcp 100-200", 1000),
remoteRuleWithName("test-udp", "out:allow udp 200-300", 1002),
},
InAdds: []cloudprovider.SecurityRule{},
OutAdds: []cloudprovider.SecurityRule{
remoteRuleWithName("", "out:allow any", 2097),
},
InDels: []cloudprovider.SecurityRule{},
OutDels: []cloudprovider.SecurityRule{},
},
{
Name: "Test add rules",
LocalRules: secrules.SecurityRuleSet{
localRuleWithPriority("in:allow tcp", 100),
localRuleWithPriority("in:allow udp", 99),
localRuleWithPriority("out:deny any", 1),
},
RemoteRules: []cloudprovider.SecurityRule{
remoteRuleWithName("allow-ssh", "in:allow tcp 22", 300),
},
Common: []cloudprovider.SecurityRule{},
InAdds: []cloudprovider.SecurityRule{
remoteRuleWithName("", "in:allow tcp", 2097),
remoteRuleWithName("", "in:allow udp", 2097),
},
OutAdds: []cloudprovider.SecurityRule{},
InDels: []cloudprovider.SecurityRule{
remoteRuleWithName("allow-ssh", "in:allow tcp 22", 300),
},
OutDels: []cloudprovider.SecurityRule{},
},
{
Name: "Test insert rules",
LocalRules: secrules.SecurityRuleSet{
localRuleWithPriority("in:allow tcp", 100),
localRuleWithPriority("in:allow udp", 99),
localRuleWithPriority("in:allow icmp", 98),
localRuleWithPriority("out:deny any", 1),
},
RemoteRules: []cloudprovider.SecurityRule{
remoteRuleWithName("allow-tcp", "in:allow tcp", 300),
remoteRuleWithName("allow-icmp", "in:allow icmp", 400),
},
Common: []cloudprovider.SecurityRule{
remoteRuleWithName("allow-tcp", "in:allow tcp", 300),
remoteRuleWithName("allow-icmp", "in:allow icmp", 400),
},
InAdds: []cloudprovider.SecurityRule{
remoteRuleWithName("", "in:allow udp", 2097),
},
OutAdds: []cloudprovider.SecurityRule{},
InDels: []cloudprovider.SecurityRule{},
OutDels: []cloudprovider.SecurityRule{},
},
{
Name: "Test icmp rules",
LocalRules: secrules.SecurityRuleSet{
localRuleWithPriority("in:allow tcp 33", 10),
localRuleWithPriority("in:allow tcp 22", 1),
localRuleWithPriority("out:deny any", 1),
},
RemoteRules: []cloudprovider.SecurityRule{
remoteRuleWithName("allow-tcp-22", "in:allow tcp 22", 300),
},
Common: []cloudprovider.SecurityRule{
remoteRuleWithName("allow-tcp-22", "in:allow tcp 22", 300),
},
InAdds: []cloudprovider.SecurityRule{
remoteRuleWithName("", "in:allow tcp 33", 299),
},
OutAdds: []cloudprovider.SecurityRule{},
InDels: []cloudprovider.SecurityRule{},
OutDels: []cloudprovider.SecurityRule{},
},
{
Name: "Test a rules",
LocalRules: secrules.SecurityRuleSet{
localRuleWithPriority("in:allow tcp 1050", 5),
localRuleWithPriority("in:allow tcp 1011", 4),
localRuleWithPriority("in:allow tcp 1002", 3),
localRuleWithPriority("in:allow tcp 22", 2),
localRuleWithPriority("in:allow udp 55", 1),
localRuleWithPriority("out:deny any", 1),
},
RemoteRules: []cloudprovider.SecurityRule{
remoteRuleWithName("in_allow_udp_55_4014", "in:allow udp 55", 4014),
remoteRuleWithName("in_allow_tcp_22_4013", "in:allow tcp 22", 4013),
remoteRuleWithName("in_allow_tcp_1002_4012", "in:allow tcp 1002", 4012),
remoteRuleWithName("in_allow_tcp_1010_4011", "in:allow tcp 1010", 4011),
remoteRuleWithName("in_allow_tcp_1050_4010", "in:allow tcp 1050", 4010),
},
Common: []cloudprovider.SecurityRule{
remoteRuleWithName("in_allow_tcp_1050_4010", "in:allow tcp 1050", 4010),
remoteRuleWithName("in_allow_tcp_1002_4012", "in:allow tcp 1002", 4012),
remoteRuleWithName("in_allow_tcp_22_4013", "in:allow tcp 22", 4013),
remoteRuleWithName("in_allow_udp_55_4014", "in:allow udp 55", 4014),
},
InAdds: []cloudprovider.SecurityRule{
remoteRuleWithName("", "in:allow tcp 1011", 4011),
},
OutAdds: []cloudprovider.SecurityRule{},
InDels: []cloudprovider.SecurityRule{
remoteRuleWithName("in_allow_tcp_1010_4011", "in:allow tcp 1010", 4011),
},
OutDels: []cloudprovider.SecurityRule{},
},
{
Name: "Test b rules",
LocalRules: secrules.SecurityRuleSet{
localRuleWithPriority("in:allow udp 1055", 20),
localRuleWithPriority("in:allow icmp", 15),
localRuleWithPriority("in:allow tcp 1050", 5),
localRuleWithPriority("in:allow tcp 1012", 4),
localRuleWithPriority("in:allow tcp 1002", 3),
localRuleWithPriority("in:allow tcp 22", 2),
localRuleWithPriority("in:allow udp 55", 1),
localRuleWithPriority("out:deny any", 1),
},
RemoteRules: []cloudprovider.SecurityRule{
remoteRuleWithName("in_allow_udp_55_4014", "in:allow udp 55", 4014),
remoteRuleWithName("in_allow_tcp_22_4013", "in:allow tcp 22", 4013),
remoteRuleWithName("in_allow_tcp_1002_4012", "in:allow tcp 1002", 4012),
remoteRuleWithName("in_allow_tcp_1012_4011", "in:allow tcp 1012", 4011),
remoteRuleWithName("in_allow_tcp_1050_4010", "in:allow tcp 1050", 4010),
remoteRuleWithName("in_allow_tcp_1055_4009", "in:allow tcp 1055", 4009),
},
Common: []cloudprovider.SecurityRule{
remoteRuleWithName("in_allow_tcp_1050_4010", "in:allow tcp 1050", 4010),
remoteRuleWithName("in_allow_tcp_1012_4011", "in:allow tcp 1012", 4011),
remoteRuleWithName("in_allow_tcp_1002_4012", "in:allow tcp 1002", 4012),
remoteRuleWithName("in_allow_tcp_22_4013", "in:allow tcp 22", 4013),
remoteRuleWithName("in_allow_udp_55_4014", "in:allow udp 55", 4014),
},
InAdds: []cloudprovider.SecurityRule{
remoteRuleWithName("", "in:allow icmp", 2097),
remoteRuleWithName("", "in:allow udp 1055", 4013),
},
OutAdds: []cloudprovider.SecurityRule{},
InDels: []cloudprovider.SecurityRule{
remoteRuleWithName("in_allow_tcp_1055_4009", "in:allow tcp 1055", 4009),
},
OutDels: []cloudprovider.SecurityRule{},
},
}
for _, d := range data {
t.Logf("check %s", d.Name)
common, inAdds, outAdds, inDels, outDels := cloudprovider.CompareRules(minPriority, maxPriority, order, d.LocalRules, d.RemoteRules, defaultInRule, defaultOutRule, isOnlyAllowRules, true)
sort.Sort(cloudprovider.SecurityRuleSet(common))
sort.Sort(cloudprovider.SecurityRuleSet(inAdds))
sort.Sort(cloudprovider.SecurityRuleSet(outAdds))
sort.Sort(cloudprovider.SecurityRuleSet(inDels))
sort.Sort(cloudprovider.SecurityRuleSet(outDels))
check(t, "common", common, d.Common)
check(t, "inAdds", inAdds, d.InAdds)
check(t, "outAdds", outAdds, d.OutAdds)
check(t, "inDels", inDels, d.InDels)
check(t, "outDels", outDels, d.OutDels)
}
}

View File

@@ -0,0 +1,70 @@
// Copyright 2019 Yunion
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package regiondrivers
import (
"sort"
"testing"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/onecloud/pkg/cloudprovider"
)
func TestCtyunRuleSync(t *testing.T) {
driver := SCtyunRegionDriver{}
maxPriority := driver.GetSecurityGroupRuleMaxPriority()
minPriority := driver.GetSecurityGroupRuleMinPriority()
defaultInRule := driver.GetDefaultSecurityGroupInRule()
defaultOutRule := driver.GetDefaultSecurityGroupOutRule()
order := driver.GetSecurityGroupRuleOrder()
isOnlyAllowRules := driver.IsOnlySupportAllowRules()
data := []TestData{
{
Name: "Test out deny rules",
LocalRules: secrules.SecurityRuleSet{
localRuleWithPriority("out:deny tcp 200", 1),
},
RemoteRules: []cloudprovider.SecurityRule{},
Common: []cloudprovider.SecurityRule{},
InAdds: []cloudprovider.SecurityRule{},
OutAdds: []cloudprovider.SecurityRule{
remoteRuleWithName("", "out:allow icmp", 0),
remoteRuleWithName("", "out:allow tcp 1-199", 0),
remoteRuleWithName("", "out:allow tcp 201-65535", 0),
remoteRuleWithName("", "out:allow udp", 0),
},
InDels: []cloudprovider.SecurityRule{},
OutDels: []cloudprovider.SecurityRule{},
},
}
for _, d := range data {
t.Logf("check %s", d.Name)
common, inAdds, outAdds, inDels, outDels := cloudprovider.CompareRules(minPriority, maxPriority, order, d.LocalRules, d.RemoteRules, defaultInRule, defaultOutRule, isOnlyAllowRules, true)
sort.Sort(cloudprovider.SecurityRuleSet(common))
sort.Sort(cloudprovider.SecurityRuleSet(inAdds))
sort.Sort(cloudprovider.SecurityRuleSet(outAdds))
sort.Sort(cloudprovider.SecurityRuleSet(inDels))
sort.Sort(cloudprovider.SecurityRuleSet(outDels))
check(t, "common", common, d.Common)
check(t, "inAdds", inAdds, d.InAdds)
check(t, "outAdds", outAdds, d.OutAdds)
check(t, "inDels", inDels, d.InDels)
check(t, "outDels", outDels, d.OutDels)
}
}

Some files were not shown because too many files have changed in this diff Show More