guestnetworksecgroups.go 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648
  1. // Copyright 2019 Yunion
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package models
  15. import (
  16. "context"
  17. "fmt"
  18. "path"
  19. "strconv"
  20. "gopkg.in/fatih/set.v0"
  21. "yunion.io/x/jsonutils"
  22. "yunion.io/x/log"
  23. "yunion.io/x/pkg/errors"
  24. "yunion.io/x/pkg/utils"
  25. "yunion.io/x/sqlchemy"
  26. api "yunion.io/x/onecloud/pkg/apis/compute"
  27. "yunion.io/x/onecloud/pkg/cloudcommon/db"
  28. "yunion.io/x/onecloud/pkg/cloudcommon/validators"
  29. "yunion.io/x/onecloud/pkg/httperrors"
  30. "yunion.io/x/onecloud/pkg/mcclient"
  31. "yunion.io/x/onecloud/pkg/util/logclient"
  32. "yunion.io/x/onecloud/pkg/util/stringutils2"
  33. )
  34. // +onecloud:swagger-gen-model-singular=guestnetworksecgroup
  35. // +onecloud:swagger-gen-model-plural=guestnetworksecgroups
  36. type SGuestnetworksecgroupManager struct {
  37. db.SResourceBaseManager
  38. SGuestResourceBaseManager
  39. SSecurityGroupResourceBaseManager
  40. SCloudregionResourceBaseManager
  41. SManagedResourceBaseManager
  42. SVpcResourceBaseManager
  43. }
  44. var GuestnetworksecgroupManager *SGuestnetworksecgroupManager
  45. func init() {
  46. db.InitManager(func() {
  47. GuestnetworksecgroupManager = &SGuestnetworksecgroupManager{
  48. SResourceBaseManager: db.NewResourceBaseManager(
  49. SGuestnetworksecgroup{},
  50. "guestnetworksecgroups_tbl",
  51. "guestnetworksecgroup",
  52. "guestnetworksecgroups",
  53. ),
  54. }
  55. GuestnetworksecgroupManager.SetVirtualObject(GuestnetworksecgroupManager)
  56. })
  57. }
  58. // +onecloud:model-api-gen
  59. type SGuestnetworksecgroup struct {
  60. db.SResourceBase
  61. RowId int64 `primary:"true" auto_increment:"true" list:"user"`
  62. GuestId string `width:"36" charset:"ascii" nullable:"false" list:"user" create:"required" index:"true"`
  63. SSecurityGroupResourceBase `width:"36" charset:"ascii" nullable:"false" list:"user" create:"required"`
  64. NetworkIndex int `nullable:"false" list:"user" update:"user"`
  65. Admin bool `nullable:"false" default:"false" list:"user" create:"optional"`
  66. }
  67. func (manager *SGuestnetworksecgroupManager) GetSlaveFieldName() string {
  68. return "secgroup_id"
  69. }
  70. func (self *SGuestnetworksecgroup) Delete(ctx context.Context, userCred mcclient.TokenCredential) error {
  71. return db.DeleteModel(ctx, userCred, self)
  72. }
  73. func (manager *SGuestnetworksecgroupManager) ListItemFilter(
  74. ctx context.Context,
  75. q *sqlchemy.SQuery,
  76. userCred mcclient.TokenCredential,
  77. query api.GuestnetworksecgroupListInput,
  78. ) (*sqlchemy.SQuery, error) {
  79. var err error
  80. q, err = manager.SGuestResourceBaseManager.ListItemFilter(ctx, q, userCred, query.ServerFilterListInput)
  81. if err != nil {
  82. return nil, errors.Wrap(err, "SGuestJointsManager.ListItemFilter")
  83. }
  84. q, err = manager.SSecurityGroupResourceBaseManager.ListItemFilter(ctx, q, userCred, query.SecgroupFilterListInput)
  85. if err != nil {
  86. return nil, errors.Wrap(err, "SSecurityGroupResourceBaseManager.ListItemFilter")
  87. }
  88. if query.NetworkIndex != nil {
  89. q = q.Equals("network_index", *query.NetworkIndex)
  90. }
  91. if query.IsAdmin {
  92. q = q.IsFalse("admin")
  93. }
  94. return q, nil
  95. }
  96. func (manager *SGuestnetworksecgroupManager) OrderByExtraFields(
  97. ctx context.Context,
  98. q *sqlchemy.SQuery,
  99. userCred mcclient.TokenCredential,
  100. query api.GuestnetworksecgroupListInput,
  101. ) (*sqlchemy.SQuery, error) {
  102. var err error
  103. q, err = manager.SGuestResourceBaseManager.OrderByExtraFields(ctx, q, userCred, query.ServerFilterListInput)
  104. if err != nil {
  105. return nil, errors.Wrap(err, "SGuestJointsManager.OrderByExtraFields")
  106. }
  107. q, err = manager.SSecurityGroupResourceBaseManager.OrderByExtraFields(ctx, q, userCred, query.SecgroupFilterListInput)
  108. if err != nil {
  109. return nil, errors.Wrap(err, "SSecurityGroupResourceBaseManager.OrderByExtraFields")
  110. }
  111. return q, nil
  112. }
  113. func (manager *SGuestnetworksecgroupManager) ListItemExportKeys(ctx context.Context,
  114. q *sqlchemy.SQuery,
  115. userCred mcclient.TokenCredential,
  116. keys stringutils2.SSortedStrings,
  117. ) (*sqlchemy.SQuery, error) {
  118. var err error
  119. q, err = manager.SGuestResourceBaseManager.ListItemExportKeys(ctx, q, userCred, keys)
  120. if err != nil {
  121. return nil, errors.Wrap(err, "SGuestJointsManager.ListItemExportKeys")
  122. }
  123. if keys.ContainsAny(manager.SSecurityGroupResourceBaseManager.GetExportKeys()...) {
  124. q, err = manager.SSecurityGroupResourceBaseManager.ListItemExportKeys(ctx, q, userCred, keys)
  125. if err != nil {
  126. return nil, errors.Wrap(err, "SSecurityGroupResourceBaseManager.ListItemExportKeys")
  127. }
  128. }
  129. return q, nil
  130. }
  131. func (manager *SGuestnetworksecgroupManager) FetchCustomizeColumns(
  132. ctx context.Context,
  133. userCred mcclient.TokenCredential,
  134. query jsonutils.JSONObject,
  135. objs []interface{},
  136. fields stringutils2.SSortedStrings,
  137. isList bool,
  138. ) []api.GuestnetworksecgroupDetails {
  139. rows := make([]api.GuestnetworksecgroupDetails, len(objs))
  140. guestList := make([]interface{}, len(objs))
  141. guestIds := make([]string, len(objs))
  142. guestNetworkIdx := make([]int, len(objs))
  143. secgrpIds := make([]string, len(objs))
  144. for i := range objs {
  145. secgrpIds[i] = objs[i].(*SGuestnetworksecgroup).SecgroupId
  146. guestList[i] = &SGuestResourceBase{objs[i].(*SGuestnetworksecgroup).GuestId}
  147. guestIds[i] = objs[i].(*SGuestnetworksecgroup).GuestId
  148. guestNetworkIdx[i] = objs[i].(*SGuestnetworksecgroup).NetworkIndex
  149. }
  150. groups := make(map[string]SSecurityGroup)
  151. err := db.FetchStandaloneObjectsByIds(SecurityGroupManager, secgrpIds, groups)
  152. if err != nil {
  153. log.Errorf("FetchStandaloneObjectsByIds fail %s", err)
  154. return nil
  155. }
  156. guestRows := manager.SGuestResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, guestList, fields, isList)
  157. gns, err := GuestnetworkManager.fetchGuestnetworksByGuestnetworkIndex(guestIds, guestNetworkIdx)
  158. if err != nil {
  159. log.Errorf("failed fetchGuestnetworksByGuestnetworkIndex")
  160. return nil
  161. }
  162. regionList := make([]interface{}, len(objs))
  163. managerList := make([]interface{}, len(objs))
  164. vpcList := make([]interface{}, len(objs))
  165. projectList := make([]interface{}, len(objs))
  166. for i := range rows {
  167. secgroupId := objs[i].(*SGuestnetworksecgroup).SecgroupId
  168. guestId := objs[i].(*SGuestnetworksecgroup).GuestId
  169. networkIndex := objs[i].(*SGuestnetworksecgroup).NetworkIndex
  170. rows[i].GuestResourceInfo = guestRows[i]
  171. rows[i].NetworkIndex = networkIndex
  172. rows[i].Admin = objs[i].(*SGuestnetworksecgroup).Admin
  173. rows[i].GuestNetwork = path.Join(guestId, secgroupId, strconv.Itoa(rows[i].NetworkIndex))
  174. if group, ok := groups[secgrpIds[i]]; ok {
  175. rows[i].Secgroup = group.Name
  176. rows[i].CloudregionId = group.CloudregionId
  177. rows[i].ManagerId = group.ManagerId
  178. rows[i].VpcId = group.VpcId
  179. rows[i].SecgroupStatus = group.Status
  180. rows[i].ProjectId = group.ProjectId
  181. secgroup := group
  182. projectList[i] = &secgroup
  183. }
  184. regionList[i] = &SCloudregionResourceBase{rows[i].CloudregionId}
  185. managerList[i] = &SManagedResourceBase{rows[i].ManagerId}
  186. vpcList[i] = &SVpcResourceBase{rows[i].VpcId}
  187. key := fmt.Sprintf("%s/%d", guestId, networkIndex)
  188. if gn, ok := gns[key]; ok {
  189. rows[i].MacAddr = gn.MacAddr
  190. rows[i].IpAddr = gn.IpAddr
  191. rows[i].Ip6Addr = gn.Ip6Addr
  192. rows[i].Ifname = gn.Ifname
  193. if network, _ := gn.GetNetwork(); network != nil {
  194. rows[i].NetworkId = gn.NetworkId
  195. rows[i].NetworkName = network.Name
  196. }
  197. }
  198. }
  199. projRows := SecurityGroupManager.SProjectizedResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, projectList, fields, isList)
  200. regionRows := manager.SCloudregionResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, regionList, fields, isList)
  201. managerRows := manager.SManagedResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, managerList, fields, isList)
  202. vpcRows := manager.SVpcResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, vpcList, fields, isList)
  203. for i := range rows {
  204. rows[i].ProjectizedResourceInfo = projRows[i]
  205. rows[i].CloudregionResourceInfo = regionRows[i]
  206. rows[i].ManagedResourceInfo = managerRows[i]
  207. rows[i].Vpc = vpcRows[i].Vpc
  208. }
  209. return rows
  210. }
  211. func (manager *SGuestnetworkManager) fetchGuestnetworksByGuestnetworkIndex(guestIds []string, networkIndex []int) (map[string]SGuestnetwork, error) {
  212. q := manager.Query()
  213. q = q.In("guest_id", guestIds)
  214. q = q.In("index", networkIndex)
  215. gns := make([]SGuestnetwork, 0)
  216. err := q.All(&gns)
  217. if err != nil {
  218. return nil, err
  219. }
  220. res := map[string]SGuestnetwork{}
  221. for i := range gns {
  222. key := fmt.Sprintf("%s/%d", gns[i].GuestId, gns[i].Index)
  223. if _, ok := res[key]; !ok {
  224. res[key] = gns[i]
  225. }
  226. }
  227. return res, nil
  228. }
  229. func (manager *SGuestnetworksecgroupManager) QueryDistinctExtraField(q *sqlchemy.SQuery, field string) (*sqlchemy.SQuery, error) {
  230. q, err := manager.SResourceBaseManager.QueryDistinctExtraField(q, field)
  231. if err == nil {
  232. return q, nil
  233. }
  234. q, err = manager.SGuestResourceBaseManager.QueryDistinctExtraField(q, field)
  235. if err == nil {
  236. return q, nil
  237. }
  238. q, err = manager.SSecurityGroupResourceBaseManager.QueryDistinctExtraField(q, field)
  239. if err == nil {
  240. return q, nil
  241. }
  242. return q, httperrors.ErrNotFound
  243. }
  244. func (manager *SGuestnetworksecgroupManager) QueryDistinctExtraFields(q *sqlchemy.SQuery, resource string, fields []string) (*sqlchemy.SQuery, error) {
  245. q, err := manager.SResourceBaseManager.QueryDistinctExtraFields(q, resource, fields)
  246. if err == nil {
  247. return q, nil
  248. }
  249. q, err = manager.SGuestResourceBaseManager.QueryDistinctExtraFields(q, resource, fields)
  250. if err == nil {
  251. return q, nil
  252. }
  253. q, err = manager.SSecurityGroupResourceBaseManager.QueryDistinctExtraFields(q, resource, fields)
  254. if err == nil {
  255. return q, nil
  256. }
  257. return q, httperrors.ErrNotFound
  258. }
  259. func (manager *SGuestnetworksecgroupManager) GetGuestnetworksecgroups(guestId string, networkIndex int) ([]SSecurityGroup, error) {
  260. q := GuestnetworksecgroupManager.Query("secgroup_id").Equals("guest_id", guestId)
  261. if networkIndex >= 0 {
  262. q = q.Equals("network_index", networkIndex)
  263. }
  264. subQ := q.SubQuery()
  265. secgrpQuery := SecurityGroupManager.Query()
  266. secgrpQuery = secgrpQuery.In("id", subQ)
  267. secgroups := []SSecurityGroup{}
  268. err := db.FetchModelObjects(SecurityGroupManager, secgrpQuery, &secgroups)
  269. if err != nil {
  270. return nil, errors.Wrapf(err, "db.FetchModelObjects")
  271. }
  272. return secgroups, nil
  273. }
  274. // guest network attach secgroup
  275. func (self *SGuest) PerformAddNetworkSecgroup(
  276. ctx context.Context,
  277. userCred mcclient.TokenCredential,
  278. query jsonutils.JSONObject,
  279. input api.GuestNetworkAddSecgroupInput,
  280. ) (jsonutils.JSONObject, error) {
  281. if !utils.IsInStringArray(self.Status, []string{api.VM_READY, api.VM_RUNNING, api.VM_SUSPEND}) {
  282. return nil, httperrors.NewInputParameterError("Cannot add security groups in status %s", self.Status)
  283. }
  284. if input.NetworkIndex == nil || *input.NetworkIndex < 0 {
  285. return nil, httperrors.NewBadRequestError("input network index %#v is invalid", input.NetworkIndex)
  286. }
  287. driver, _ := self.GetDriver()
  288. maxCount := driver.GetMaxSecurityGroupCount()
  289. if maxCount == 0 {
  290. return nil, httperrors.NewUnsupportOperationError("Cannot add security groups for hypervisor %s", self.Hypervisor)
  291. }
  292. if len(input.SecgroupIds) == 0 {
  293. return nil, httperrors.NewMissingParameterError("secgroup_ids")
  294. }
  295. guestnetwork, err := self.getGuestnetworkByIndex(*input.NetworkIndex)
  296. if err != nil {
  297. return nil, httperrors.NewGeneralError(errors.Wrap(err, "getGuestnetworkByIndex"))
  298. }
  299. secgroups, err := GuestnetworksecgroupManager.GetGuestnetworksecgroups(self.Id, *input.NetworkIndex)
  300. if err != nil {
  301. return nil, httperrors.NewGeneralError(errors.Wrap(err, "GetGuestnetworksecgroups"))
  302. }
  303. if len(secgroups)+len(input.SecgroupIds) > maxCount {
  304. return nil, httperrors.NewUnsupportOperationError("guest %s band to up to %d security groups", self.Name, maxCount)
  305. }
  306. network, err := guestnetwork.GetNetwork()
  307. if err != nil {
  308. return nil, httperrors.NewGeneralError(errors.Wrap(err, "GetNetwork"))
  309. }
  310. vpc, err := network.GetVpc()
  311. if err != nil {
  312. return nil, errors.Wrap(err, "GetVpc")
  313. }
  314. secgroupIds := []string{}
  315. for _, secgroup := range secgroups {
  316. secgroupIds = append(secgroupIds, secgroup.Id)
  317. }
  318. secgroupNames := []string{}
  319. for i := range input.SecgroupIds {
  320. secObj, err := validators.ValidateModel(ctx, userCred, SecurityGroupManager, &input.SecgroupIds[i])
  321. if err != nil {
  322. return nil, err
  323. }
  324. secgroup := secObj.(*SSecurityGroup)
  325. if utils.IsInStringArray(secObj.GetId(), secgroupIds) {
  326. return nil, httperrors.NewInputParameterError(
  327. "security group %s has already been assigned to guest %s network %d",
  328. secObj.GetName(), self.GetName(), input.NetworkIndex)
  329. }
  330. err = vpc.CheckSecurityGroupConsistent(secgroup)
  331. if err != nil {
  332. return nil, err
  333. }
  334. secgroupIds = append(secgroupIds, secgroup.GetId())
  335. secgroupNames = append(secgroupNames, secgroup.Name)
  336. }
  337. err = self.SaveNetworkSecgroups(ctx, userCred, secgroupIds, *input.NetworkIndex)
  338. if err != nil {
  339. return nil, httperrors.NewGeneralError(errors.Wrap(err, "SaveNetworkSecgroups"))
  340. }
  341. notes := map[string][]string{"secgroups": secgroupNames}
  342. logclient.AddActionLogWithContext(ctx, self, logclient.ACT_VM_ASSIGNSECGROUP, notes, userCred, true)
  343. return nil, self.StartSyncTask(ctx, userCred, true, "")
  344. }
  345. func (self *SGuest) PerformRevokeNetworkSecgroup(
  346. ctx context.Context,
  347. userCred mcclient.TokenCredential,
  348. query jsonutils.JSONObject,
  349. input api.GuestRevokeNetworkSecgroupInput,
  350. ) (jsonutils.JSONObject, error) {
  351. if !utils.IsInStringArray(self.Status, []string{api.VM_READY, api.VM_RUNNING, api.VM_SUSPEND}) {
  352. return nil, httperrors.NewInputParameterError("Cannot revoke security groups in status %s", self.Status)
  353. }
  354. if len(input.SecgroupIds) == 0 {
  355. return nil, nil
  356. }
  357. var guestnetwork *SGuestnetwork
  358. var err error
  359. if input.MacAddr != "" {
  360. guestnetwork, err = self.GetGuestnetworkByMac(input.MacAddr)
  361. } else if input.NetworkIndex != nil {
  362. guestnetwork, err = self.getGuestnetworkByIndex(*input.NetworkIndex)
  363. } else {
  364. return nil, httperrors.NewBadRequestError("no valid network index or mac addr")
  365. }
  366. if err != nil {
  367. return nil, httperrors.NewGeneralError(errors.Wrap(err, "get guest network"))
  368. }
  369. secgroups, err := GuestnetworksecgroupManager.GetGuestnetworksecgroups(self.Id, guestnetwork.Index)
  370. if err != nil {
  371. return nil, httperrors.NewGeneralError(errors.Wrap(err, "GetGuestnetworksecgroups"))
  372. }
  373. secgroupMaps := map[string]string{}
  374. for _, secgroup := range secgroups {
  375. secgroupMaps[secgroup.Id] = secgroup.Name
  376. }
  377. secgroupNames := []string{}
  378. for i := range input.SecgroupIds {
  379. secObj, err := validators.ValidateModel(ctx, userCred, SecurityGroupManager, &input.SecgroupIds[i])
  380. if err != nil {
  381. return nil, err
  382. }
  383. secgrp := secObj.(*SSecurityGroup)
  384. _, ok := secgroupMaps[secgrp.GetId()]
  385. if !ok {
  386. return nil, httperrors.NewInputParameterError("security group %s network index %d not assigned to guest %s",
  387. secgrp.GetName(), guestnetwork.Index, self.GetName())
  388. }
  389. delete(secgroupMaps, secgrp.GetId())
  390. secgroupNames = append(secgroupNames, secgrp.GetName())
  391. }
  392. secgrpIds := []string{}
  393. for secgroupId := range secgroupMaps {
  394. secgrpIds = append(secgrpIds, secgroupId)
  395. }
  396. err = self.SaveNetworkSecgroups(ctx, userCred, secgrpIds, guestnetwork.Index)
  397. if err != nil {
  398. return nil, httperrors.NewGeneralError(errors.Wrap(err, "SaveNetworkSecgroups"))
  399. }
  400. notes := map[string][]string{"secgroups": secgroupNames}
  401. logclient.AddActionLogWithContext(ctx, self, logclient.ACT_VM_REVOKESECGROUP, notes, userCred, true)
  402. return nil, self.StartSyncTask(ctx, userCred, true, "")
  403. }
  404. func (self *SGuest) PerformSetNetworkSecgroup(
  405. ctx context.Context,
  406. userCred mcclient.TokenCredential,
  407. query jsonutils.JSONObject,
  408. input api.GuestSetNetworkSecgroupInput,
  409. ) (jsonutils.JSONObject, error) {
  410. if !utils.IsInStringArray(self.Status, []string{api.VM_READY, api.VM_RUNNING, api.VM_SUSPEND}) {
  411. return nil, httperrors.NewInputParameterError("Cannot set security rules in status %s", self.Status)
  412. }
  413. driver, _ := self.GetDriver()
  414. maxCount := driver.GetMaxSecurityGroupCount()
  415. if maxCount == 0 {
  416. return nil, httperrors.NewUnsupportOperationError("Cannot set security group for this guest %s", self.Name)
  417. }
  418. if len(input.SecgroupIds) > maxCount {
  419. return nil, httperrors.NewUnsupportOperationError("guest %s band to up to %d security groups", self.Name, maxCount)
  420. }
  421. var guestnetwork *SGuestnetwork
  422. var err error
  423. if input.MacAddr != "" {
  424. guestnetwork, err = self.GetGuestnetworkByMac(input.MacAddr)
  425. } else if input.NetworkIndex != nil {
  426. guestnetwork, err = self.getGuestnetworkByIndex(*input.NetworkIndex)
  427. } else {
  428. return nil, httperrors.NewBadRequestError("no valid network index or mac addr")
  429. }
  430. if err != nil {
  431. return nil, httperrors.NewGeneralError(errors.Wrap(err, "get guest network"))
  432. }
  433. network, err := guestnetwork.GetNetwork()
  434. if err != nil {
  435. return nil, httperrors.NewGeneralError(errors.Wrap(err, "GetNetwork"))
  436. }
  437. vpc, err := network.GetVpc()
  438. if err != nil {
  439. return nil, errors.Wrap(err, "GetVpc")
  440. }
  441. secgroupIds := []string{}
  442. secgroupNames := []string{}
  443. for i := range input.SecgroupIds {
  444. secObj, err := validators.ValidateModel(ctx, userCred, SecurityGroupManager, &input.SecgroupIds[i])
  445. if err != nil {
  446. return nil, err
  447. }
  448. secgrp := secObj.(*SSecurityGroup)
  449. err = vpc.CheckSecurityGroupConsistent(secgrp)
  450. if err != nil {
  451. return nil, err
  452. }
  453. if !utils.IsInStringArray(secgrp.GetId(), secgroupIds) {
  454. secgroupIds = append(secgroupIds, secgrp.GetId())
  455. secgroupNames = append(secgroupNames, secgrp.GetName())
  456. }
  457. }
  458. err = self.SaveNetworkSecgroups(ctx, userCred, secgroupIds, guestnetwork.Index)
  459. if err != nil {
  460. return nil, httperrors.NewGeneralError(errors.Wrapf(err, "SaveNetworkSecgroups"))
  461. }
  462. notes := map[string][]string{"secgroups": secgroupNames}
  463. logclient.AddActionLogWithContext(ctx, self, logclient.ACT_VM_SETSECGROUP, notes, userCred, true)
  464. return nil, self.StartSyncTask(ctx, userCred, true, "")
  465. }
  466. func (self *SGuest) SaveNetworkSecgroups(
  467. ctx context.Context, userCred mcclient.TokenCredential, secgroupIds []string, networkIndex int,
  468. ) error {
  469. if len(secgroupIds) == 0 {
  470. return self.RevokeNetworkAllSecgroups(ctx, userCred, networkIndex)
  471. }
  472. oldIds := set.New(set.ThreadSafe)
  473. newIds := set.New(set.ThreadSafe)
  474. gnss, err := self.GetGuestNetworkSecgroups(networkIndex)
  475. if err != nil {
  476. return errors.Wrap(err, "GetGuestNetworkSecgroups")
  477. }
  478. secgroupMaps := map[string]SGuestnetworksecgroup{}
  479. for i := range gnss {
  480. oldIds.Add(gnss[i].SecgroupId)
  481. secgroupMaps[gnss[i].SecgroupId] = gnss[i]
  482. }
  483. for i := range secgroupIds {
  484. newIds.Add(secgroupIds[i])
  485. }
  486. for _, removed := range set.Difference(oldIds, newIds).List() {
  487. id := removed.(string)
  488. gns, ok := secgroupMaps[id]
  489. if ok {
  490. err = gns.Delete(ctx, userCred)
  491. if err != nil {
  492. return errors.Wrapf(err,
  493. "Delete guest network secgroup for guest %s network index %d secgroup %s",
  494. self.GetName(), networkIndex, id)
  495. }
  496. }
  497. }
  498. for _, added := range set.Difference(newIds, oldIds).List() {
  499. id := added.(string)
  500. err = self.newGuestNetworkSecgroup(ctx, id, networkIndex, false)
  501. if err != nil {
  502. return errors.Wrapf(err,
  503. "New guest network secgroup for guest %s network index %d with secgroup %s",
  504. self.GetName(), networkIndex, id)
  505. }
  506. }
  507. return nil
  508. }
  509. func (self *SGuest) newGuestNetworkSecgroup(ctx context.Context, secgroupId string, networkIndex int, isAdmin bool) error {
  510. gns := &SGuestnetworksecgroup{}
  511. gns.SetModelManager(GuestnetworksecgroupManager, gns)
  512. gns.GuestId = self.Id
  513. gns.SecgroupId = secgroupId
  514. gns.NetworkIndex = networkIndex
  515. gns.Admin = isAdmin
  516. return GuestnetworksecgroupManager.TableSpec().Insert(ctx, gns)
  517. }
  518. func (self *SGuest) GetGuestNetworkSecgroups(networkIndex int) ([]SGuestnetworksecgroup, error) {
  519. gss := []SGuestnetworksecgroup{}
  520. q := GuestnetworksecgroupManager.Query().Equals("guest_id", self.Id).Equals("network_index", networkIndex)
  521. err := db.FetchModelObjects(GuestnetworksecgroupManager, q, &gss)
  522. if err != nil {
  523. return nil, errors.Wrapf(err, "db.FetchModelObjects")
  524. }
  525. return gss, nil
  526. }
  527. func (self *SGuest) RevokeNetworkAllSecgroups(ctx context.Context, userCred mcclient.TokenCredential, networkIndex int) error {
  528. gss, err := self.GetGuestNetworkSecgroups(networkIndex)
  529. if err != nil {
  530. return errors.Wrapf(err, "GetGuestNetworkSecgroups")
  531. }
  532. for i := range gss {
  533. err = gss[i].Delete(ctx, userCred)
  534. if err != nil {
  535. return errors.Wrap(err, "Delete")
  536. }
  537. }
  538. //return self.newGuestNetworkSecgroup(ctx, options.Options.DefaultSecurityGroupId, networkIndex, false)
  539. return nil
  540. }
  541. func (self *SGuestnetworksecgroupManager) getNetworkSecgroupJson(guestId string, networkIndex int) ([]*api.SecgroupJsonDesc, error) {
  542. ret := []*api.SecgroupJsonDesc{}
  543. secgroups, err := GuestnetworksecgroupManager.GetGuestnetworksecgroups(guestId, networkIndex)
  544. if err != nil {
  545. return nil, errors.Wrap(err, "GetSecgroups")
  546. }
  547. for _, secGrp := range secgroups {
  548. ret = append(ret, secGrp.getDesc())
  549. }
  550. return ret, nil
  551. }
  552. func (self *SGuest) RevokeAllNetworkSecgroups(ctx context.Context, userCred mcclient.TokenCredential) error {
  553. gns, err := self.GetNetworks("")
  554. if err != nil {
  555. return errors.Wrap(err, "GetNetworks")
  556. }
  557. for i := range gns {
  558. gnss, err := self.GetGuestNetworkSecgroups(gns[i].Index)
  559. if err != nil {
  560. return errors.Wrap(err, "GetGuestNetworkSecgroups")
  561. }
  562. for j := range gnss {
  563. err = gnss[j].Delete(ctx, userCred)
  564. if err != nil {
  565. return errors.Wrap(err, "Delete guestnetworksecgroup")
  566. }
  567. }
  568. }
  569. return nil
  570. }