Merge branch 'release/2.3.0' of ssh://git.yunion.io/~qiujian/onecloud into hotfix/qj-remove-usercred-issystemadmin

This commit is contained in:
Qiu Jian
2018-11-30 23:26:28 +08:00
7 changed files with 159 additions and 2 deletions
+31
View File
@@ -532,4 +532,35 @@ func init() {
printObject(result)
return nil
})
type ServerAddExtraOption struct {
ID string `help:"ID or name of server"`
KEY string `help:"Option key"`
VALUE string `help:"Option value"`
}
R(&ServerAddExtraOption{}, "server-add-extra-options", "Add server extra options", func(s *mcclient.ClientSession, args *ServerAddExtraOption) error {
params := jsonutils.NewDict()
params.Add(jsonutils.NewString(args.KEY), "key")
params.Add(jsonutils.NewString(args.VALUE), "value")
result, err := modules.Servers.PerformAction(s, args.ID, "set-extra-option", params)
if err != nil {
return err
}
printObject(result)
return nil
})
type ServerRemoveExtraOption struct {
ID string `help:"ID or name of server"`
KEY string `help:"Option key"`
}
R(&ServerRemoveExtraOption{}, "server-remove-extra-options", "Remove server extra options", func(s *mcclient.ClientSession, args *ServerRemoveExtraOption) error {
params := jsonutils.NewDict()
params.Add(jsonutils.NewString(args.KEY), "key")
result, err := modules.Servers.PerformAction(s, args.ID, "del-extra-option", params)
if err != nil {
return err
}
printObject(result)
return nil
})
}
+5
View File
@@ -17,6 +17,7 @@ import (
"yunion.io/x/jsonutils"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
"yunion.io/x/onecloud/pkg/cloudcommon/db/taskman"
"yunion.io/x/onecloud/pkg/compute/models"
)
@@ -322,6 +323,10 @@ func (self *SAzureGuestDriver) RequestSyncConfigOnHost(ctx context.Context, gues
if err != nil {
return nil, err
}
lockman.LockRawObject(ctx, "secgroupcache", fmt.Sprintf("%s-%s", guest.SecgrpId, vpcID))
defer lockman.ReleaseRawObject(ctx, "secgroupcache", fmt.Sprintf("%s-%s", guest.SecgrpId, vpcID))
secgroupCache := models.SecurityGroupCacheManager.Register(ctx, task.GetUserCred(), guest.SecgrpId, vpcID, host.GetRegion().Id, host.ManagerId)
if secgroupCache == nil {
return nil, fmt.Errorf("failed to registor secgroupCache for secgroup: %s vpc: %s", guest.SecgrpId, vpcID)
@@ -10,6 +10,7 @@ import (
"yunion.io/x/pkg/util/compare"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
"yunion.io/x/onecloud/pkg/cloudcommon/db/taskman"
"yunion.io/x/onecloud/pkg/cloudprovider"
"yunion.io/x/onecloud/pkg/compute/models"
@@ -349,6 +350,10 @@ func (self *SManagedVirtualizedGuestDriver) RequestSyncConfigOnHost(ctx context.
if err != nil {
return nil, err
}
lockman.LockRawObject(ctx, "secgroupcache", fmt.Sprintf("%s-%s", guest.SecgrpId, vpcId))
defer lockman.ReleaseRawObject(ctx, "secgroupcache", fmt.Sprintf("%s-%s", guest.SecgrpId, vpcId))
secgroupCache := models.SecurityGroupCacheManager.Register(ctx, task.GetUserCred(), guest.SecgrpId, vpcId, host.GetRegion().Id, host.ManagerId)
if secgroupCache == nil {
return nil, fmt.Errorf("failed to registor secgroupCache for secgroup: %s vpc: %s", guest.SecgrpId, vpcId)
+68
View File
@@ -9,9 +9,11 @@ import (
"yunion.io/x/log"
"yunion.io/x/onecloud/pkg/httperrors"
"yunion.io/x/onecloud/pkg/mcclient"
"yunion.io/x/pkg/util/compare"
"yunion.io/x/pkg/utils"
"yunion.io/x/onecloud/pkg/cloudcommon/db"
"yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
"yunion.io/x/onecloud/pkg/cloudcommon/db/taskman"
"yunion.io/x/onecloud/pkg/cloudprovider"
"yunion.io/x/onecloud/pkg/compute/models"
@@ -348,6 +350,72 @@ func (self *SQcloudGuestDriver) OnGuestDeployTaskDataReceived(ctx context.Contex
return nil
}
func (self *SQcloudGuestDriver) RequestSyncConfigOnHost(ctx context.Context, guest *models.SGuest, host *models.SHost, task taskman.ITask) error {
taskman.LocalTaskRun(task, func() (jsonutils.JSONObject, error) {
ihost, err := host.GetIHost()
if err != nil {
return nil, err
}
iVM, err := ihost.GetIVMById(guest.ExternalId)
if err != nil {
return nil, err
}
if fwOnly, _ := task.GetParams().Bool("fw_only"); fwOnly {
iregion, err := host.GetIRegion()
if err != nil {
return nil, err
}
lockman.LockRawObject(ctx, "secgroupcache", fmt.Sprintf("%s-normal", guest.SecgrpId))
defer lockman.ReleaseRawObject(ctx, "secgroupcache", fmt.Sprintf("%s-normal", guest.SecgrpId))
secgroupCache := models.SecurityGroupCacheManager.Register(ctx, task.GetUserCred(), guest.SecgrpId, "normal", host.GetRegion().Id, host.ManagerId)
if secgroupCache == nil {
return nil, fmt.Errorf("failed to registor secgroupCache for secgroup: %s", guest.SecgrpId)
}
extID, err := iregion.SyncSecurityGroup(secgroupCache.ExternalId, "normal", guest.GetSecgroupName(), "", guest.GetSecRules())
if err != nil {
return nil, err
}
if err = secgroupCache.SetExternalId(extID); err != nil {
return nil, err
}
return nil, iVM.AssignSecurityGroup(extID)
}
iDisks, err := iVM.GetIDisks()
if err != nil {
return nil, err
}
disks := make([]models.SDisk, 0)
for _, guestdisk := range guest.GetDisks() {
disk := guestdisk.GetDisk()
disks = append(disks, *disk)
}
added := make([]models.SDisk, 0)
commondb := make([]models.SDisk, 0)
commonext := make([]cloudprovider.ICloudDisk, 0)
removed := make([]cloudprovider.ICloudDisk, 0)
if err := compare.CompareSets(disks, iDisks, &added, &commondb, &commonext, &removed); err != nil {
return nil, err
}
for _, disk := range removed {
if err := iVM.DetachDisk(disk.GetId()); err != nil {
return nil, err
}
}
for _, disk := range added {
if err := iVM.AttachDisk(disk.ExternalId); err != nil {
return nil, err
}
}
return nil, nil
})
return nil
}
func (self *SQcloudGuestDriver) AllowReconfigGuest() bool {
return true
}
+42
View File
@@ -1738,3 +1738,45 @@ func (self *SGuest) PerformUserData(ctx context.Context, userCred mcclient.Token
}
return nil, nil
}
func (self *SGuest) AllowPerformSetExtraOption(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) bool {
return userCred.IsSystemAdmin()
}
func (self *SGuest) PerformSetExtraOption(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) (jsonutils.JSONObject, error) {
key, err := data.GetString("key")
if err != nil {
return nil, httperrors.NewBadRequestError("Option key required")
}
value, _ := data.GetString("value")
extraOptions := self.GetExtraOptions(userCred)
extraOptions.Set(key, jsonutils.NewString(value))
return nil, self.SetExtraOptions(ctx, userCred, extraOptions)
}
func (self *SGuest) GetExtraOptions(userCred mcclient.TokenCredential) *jsonutils.JSONDict {
options := self.GetMetadataJson("extra_options", userCred)
o, ok := options.(*jsonutils.JSONDict)
if ok {
return o
}
return jsonutils.NewDict()
}
func (self *SGuest) SetExtraOptions(ctx context.Context, userCred mcclient.TokenCredential, extraOptions *jsonutils.JSONDict) error {
return self.SetMetadata(ctx, "extra_options", extraOptions, userCred)
}
func (self *SGuest) AllowPerformDelExtraOption(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) bool {
return userCred.IsSystemAdmin()
}
func (self *SGuest) PerformDelExtraOption(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) (jsonutils.JSONObject, error) {
key, err := data.GetString("key")
if err != nil {
return nil, httperrors.NewBadRequestError("Option key required")
}
extraOptions := self.GetExtraOptions(userCred)
extraOptions.Remove(key)
return nil, self.SetExtraOptions(ctx, userCred, extraOptions)
}
+4
View File
@@ -282,6 +282,10 @@ func (self *SSecurityGroupRule) String() string {
return fields[0] + strings.Join(fields[1:], " ")
}
func (self *SSecurityGroupRule) toRule() (*secrules.SecurityRule, error) {
return secrules.ParseSecurityRule(self.String())
}
func (self *SSecurityGroupRule) SingleRules() ([]secrules.SecurityRule, error) {
rules := make([]secrules.SecurityRule, 0)
ruleStr := self.String()
+4 -2
View File
@@ -124,11 +124,13 @@ func (self *SSecurityGroup) getSecurityRules(direction string) (rules []SSecurit
func (self *SSecurityGroup) getSecRules(direction string) []secrules.SecurityRule {
rules := make([]secrules.SecurityRule, 0)
for _, _rule := range self.getSecurityRules(direction) {
singleRules, err := _rule.SingleRules()
//这里没必要拆分为单个单个的端口,到公有云那边适配
rule, err := _rule.toRule()
if err != nil {
log.Errorf(err.Error())
continue
}
rules = append(rules, singleRules...)
rules = append(rules, *rule)
}
return rules
}