2014-09-08 11:50:25 +02:00
/* ------------------------------------------------------------------------ */
2016-05-04 12:33:23 +02:00
/* Copyright 2002-2016, OpenNebula Project, OpenNebula Systems */
2014-09-08 11:50:25 +02:00
/* */
/* Licensed under the Apache License, Version 2.0 (the "License"); you may */
/* not use this file except in compliance with the License. You may obtain */
/* a copy of the License at */
/* */
/* http://www.apache.org/licenses/LICENSE-2.0 */
/* */
/* Unless required by applicable law or agreed to in writing, software */
/* distributed under the License is distributed on an "AS IS" BASIS, */
/* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. */
/* See the License for the specific language governing permissions and */
/* limitations under the License. */
/* -------------------------------------------------------------------------*/
# ifndef SECURITYGROUP_H_
# define SECURITYGROUP_H_
# include "PoolObjectSQL.h"
2014-09-09 18:13:52 +02:00
# include "ObjectCollection.h"
2014-09-08 11:50:25 +02:00
using namespace std ;
/**
* The SecurityGroup class .
*/
class SecurityGroup : public PoolObjectSQL
{
public :
/**
* Function to print the SecurityGroup object into a string in XML format
* @ param xml the resulting XML string
* @ return a reference to the generated string
*/
string & to_xml ( string & xml ) const ;
/**
* Rebuilds the object from an xml formatted string
* @ param xml_str The xml - formatted string
*
* @ return 0 on success , - 1 otherwise
*/
int from_xml ( const string & xml_str ) ;
/**
* Returns a copy of the Template
* @ return A copy of the Template
*/
Template * clone_template ( ) const
{
2014-10-16 17:10:52 +02:00
return new Template ( * obj_template ) ;
2014-09-08 11:50:25 +02:00
} ;
2014-09-09 18:13:52 +02:00
/* ---------------------------------------------------------------------- */
/* Access VM Counter */
/* ---------------------------------------------------------------------- */
/**
2016-03-01 23:31:31 +01:00
* Adds a VM ID to the security group ( up - to - date set )
2014-09-09 18:13:52 +02:00
* @ param vm_id The new id
*
* @ return 0 on success , - 1 if the ID was already in the set
*/
int add_vm ( int vm_id )
{
2016-03-01 23:31:31 +01:00
return updated . add ( vm_id ) ;
2014-09-09 18:13:52 +02:00
}
/**
2016-03-01 23:31:31 +01:00
* Deletes a VM ID from the security Group ( any of the sets )
2014-09-09 18:13:52 +02:00
* @ param vm_id The id
*/
2016-03-01 23:31:31 +01:00
void del_vm ( int vm_id )
2014-09-09 18:13:52 +02:00
{
2016-03-01 23:31:31 +01:00
if ( updated . del ( vm_id ) = = 0 )
{
return ;
}
if ( updating . del ( vm_id ) = = 0 )
{
return ;
}
if ( error . del ( vm_id ) = = 0 )
{
return ;
}
outdated . del ( vm_id ) ;
2014-09-09 18:13:52 +02:00
}
/**
* Returns how many VMs are using the security group .
* @ return how many IDs are there in the set .
*/
int get_vms ( ) const
{
2016-03-01 23:31:31 +01:00
return updated . size ( ) + updating . size ( ) + error . size ( ) + outdated . size ( ) ;
2014-09-09 18:13:52 +02:00
}
2014-09-10 18:59:10 +02:00
/**
* Returns a group of Vector Attributes , in the form
* SECURITY_GROUP_RULE = [ SECURITY_GROUP_ID = oid , . . . ]
*
* New objects are allocated , and must be deleted by the calling method
*
* @ return a group of vector attributes
*/
2014-11-11 16:26:34 +01:00
void get_rules ( vector < VectorAttribute * > & result ) const ;
2014-09-10 18:59:10 +02:00
2016-03-01 23:31:31 +01:00
/**
* Commit SG changes to associated VMs
* @ param recover , if true It will propagate the changes to VMs in error
* and those being updated . Otherwise all VMs associated with the SG will
* be updated
*/
void commit ( bool recover )
{
if ( ! recover )
{
outdated < < updated ;
updated . clear ( ) ;
}
outdated < < updating < < error ;
updating . clear ( ) ;
error . clear ( ) ;
} ;
/**
* Functions to manipulate the vm collection id ' s
*/
int get_outdated ( int & id )
{
return outdated . pop ( id ) ;
}
int add_updating ( int id )
{
return updating . add ( id ) ;
}
int del_updating ( int id )
{
return updating . del ( id ) ;
}
int add_error ( int id )
{
return error . add ( id ) ;
}
2014-09-08 11:50:25 +02:00
private :
// -------------------------------------------------------------------------
// Friends
// -------------------------------------------------------------------------
friend class SecurityGroupPool ;
// *************************************************************************
// Constructor
// *************************************************************************
SecurityGroup ( int _uid ,
int _gid ,
const string & _uname ,
const string & _gname ,
int _umask ,
Template * sgroup_template ) ;
~ SecurityGroup ( ) ;
2014-11-13 16:00:03 +01:00
/**
* Check that a rule is valid
* @ param rule as a VectorAttribute
* @ param error describing the problem if any
* @ return true if the rule is valid
*/
bool isValidRule ( const VectorAttribute * rule , string & error ) const ;
/**
* Checks the new rules
* @ param error string describing the error if any
* @ return 0 on success
*/
int post_update_template ( string & error ) ;
2014-09-08 11:50:25 +02:00
// *************************************************************************
// DataBase implementation (Private)
// *************************************************************************
static const char * db_names ;
static const char * db_bootstrap ;
static const char * table ;
/**
* Execute an INSERT or REPLACE Sql query .
* @ param db The SQL DB
* @ param replace Execute an INSERT or a REPLACE
* @ param error_str Returns the error reason , if any
* @ return 0 one success
*/
int insert_replace ( SqlDB * db , bool replace , string & error_str ) ;
/**
* Bootstraps the database table ( s ) associated to the SecurityGroup
* @ return 0 on success
*/
static int bootstrap ( SqlDB * db )
{
ostringstream oss ( SecurityGroup : : db_bootstrap ) ;
2017-04-21 19:16:45 +02:00
return db - > exec_local_wr ( oss ) ;
2014-09-08 11:50:25 +02:00
} ;
/**
* Writes the SecurityGroup in the database .
* @ param db pointer to the db
* @ return 0 on success
*/
int insert ( SqlDB * db , string & error_str ) ;
/**
* Writes / updates the SecurityGroup ' s data fields in the database .
* @ param db pointer to the db
* @ return 0 on success
*/
int update ( SqlDB * db )
{
string error_str ;
return insert_replace ( db , true , error_str ) ;
}
/**
* Factory method for SecurityGroup templates
*/
Template * get_new_template ( ) const
{
return new Template ;
}
2014-09-09 18:13:52 +02:00
/**
2016-03-01 23:31:31 +01:00
* These collections stores the collection of VMs in the security
* group and manages the update process of a Security Group
* - updated VMs using the last version of the sg rules
* - outdated VMs with a previous version of the security group
* - updating VMs being updated , action sent to the drivers
* - error VMs that fail to update because of a wrong state or driver error
2014-09-09 18:13:52 +02:00
*/
2016-03-01 23:31:31 +01:00
ObjectCollection updated ;
ObjectCollection outdated ;
ObjectCollection updating ;
ObjectCollection error ;
2014-09-08 11:50:25 +02:00
} ;
# endif /*SECURITYGROUP_H_*/