mirror of
https://github.com/xcat2/confluent.git
synced 2026-09-29 00:31:09 +00:00
Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| c3d14977f2 | |||
| 31d19e9398 | |||
| ea533e64c6 | |||
| 4fe84ca6dc | |||
| 6f55a4ffe0 |
@@ -169,6 +169,7 @@ def set_port_tsm(s, port, model):
|
||||
raise Exception("Unsupported port for TSM")
|
||||
timer = 15
|
||||
while timer:
|
||||
timer = timer - 1
|
||||
time.sleep(1.0)
|
||||
sys.stdout.write('.')
|
||||
sys.stdout.flush()
|
||||
@@ -178,7 +179,7 @@ def set_port_tsm(s, port, model):
|
||||
elif port == 'dedicated':
|
||||
iface = 1
|
||||
s.raw_command(0x32, 0x71, b'\x00\x01\x03')
|
||||
rsp = s.raw_command(0x32, 0x72, bytearray(4, iface, 0))
|
||||
rsp = s.raw_command(0x32, 0x72, bytearray([4, iface, 0]))
|
||||
print('Complete')
|
||||
return int(rsp['data'][0])
|
||||
|
||||
@@ -261,16 +262,18 @@ def set_ipv4(s, ipaddr, channel):
|
||||
return
|
||||
rsp = int(s.raw_command(0xc, 2, bytearray([channel, 4, 0, 0]))['data'][1]) & 0b1111
|
||||
if rsp != 1:
|
||||
sys.stdout.print("Changing configuration to static...")
|
||||
sys.stdout.write("Changing configuration to static...")
|
||||
sys.stdout.flush()
|
||||
resp = s.raw_command(0xc, 1, bytearray([channel, 4, 1]))
|
||||
tries = 0
|
||||
while rsp != 1 and tries < 30:
|
||||
sys.stdout.write('.')
|
||||
sys.stdout.flush()
|
||||
tries += 1
|
||||
time.sleep(0.5)
|
||||
rsp = int(s.raw_command(0xc, 2, bytearray([channel, 4, 0, 0]))['data'][1]) & 0b1111
|
||||
sys.stdout.write('Complete')
|
||||
sys.stdout.write('Complete\n')
|
||||
sys.stdout.flush()
|
||||
print('Setting IP to {}'.format(oipaddr))
|
||||
s.raw_command(0xc, 1, bytearray([channel, 3]) + ipaddr)
|
||||
|
||||
@@ -321,7 +324,9 @@ def main():
|
||||
vendor = open('/sys/devices/virtual/dmi/id/sys_vendor').read()
|
||||
vendor = vendor.strip()
|
||||
try:
|
||||
model = open('/sys/devices/virtual/dmi/id/product_sku').read()
|
||||
model = open('/sys/devices/virtual/dmi/id/product_sku').read().strip()
|
||||
if model == 'none':
|
||||
raise Exception('No SKU')
|
||||
except Exception:
|
||||
model = open('/sys/devices/virtual/dmi/id/product_name').read()
|
||||
if vendor in ('Lenovo', 'IBM'):
|
||||
|
||||
@@ -169,6 +169,7 @@ def set_port_tsm(s, port, model):
|
||||
raise Exception("Unsupported port for TSM")
|
||||
timer = 15
|
||||
while timer:
|
||||
timer = timer - 1
|
||||
time.sleep(1.0)
|
||||
sys.stdout.write('.')
|
||||
sys.stdout.flush()
|
||||
@@ -178,7 +179,7 @@ def set_port_tsm(s, port, model):
|
||||
elif port == 'dedicated':
|
||||
iface = 1
|
||||
s.raw_command(0x32, 0x71, b'\x00\x01\x03')
|
||||
rsp = s.raw_command(0x32, 0x72, bytearray(4, iface, 0))
|
||||
rsp = s.raw_command(0x32, 0x72, bytearray([4, iface, 0]))
|
||||
print('Complete')
|
||||
return int(rsp['data'][0])
|
||||
|
||||
@@ -261,16 +262,18 @@ def set_ipv4(s, ipaddr, channel):
|
||||
return
|
||||
rsp = int(s.raw_command(0xc, 2, bytearray([channel, 4, 0, 0]))['data'][1]) & 0b1111
|
||||
if rsp != 1:
|
||||
sys.stdout.print("Changing configuration to static...")
|
||||
sys.stdout.write("Changing configuration to static...")
|
||||
sys.stdout.flush()
|
||||
resp = s.raw_command(0xc, 1, bytearray([channel, 4, 1]))
|
||||
tries = 0
|
||||
while rsp != 1 and tries < 30:
|
||||
sys.stdout.write('.')
|
||||
sys.stdout.flush()
|
||||
tries += 1
|
||||
time.sleep(0.5)
|
||||
rsp = int(s.raw_command(0xc, 2, bytearray([channel, 4, 0, 0]))['data'][1]) & 0b1111
|
||||
sys.stdout.write('Complete')
|
||||
sys.stdout.write('Complete\n')
|
||||
sys.stdout.flush()
|
||||
print('Setting IP to {}'.format(oipaddr))
|
||||
s.raw_command(0xc, 1, bytearray([channel, 3]) + ipaddr)
|
||||
|
||||
@@ -321,7 +324,9 @@ def main():
|
||||
vendor = open('/sys/devices/virtual/dmi/id/sys_vendor').read()
|
||||
vendor = vendor.strip()
|
||||
try:
|
||||
model = open('/sys/devices/virtual/dmi/id/product_sku').read()
|
||||
model = open('/sys/devices/virtual/dmi/id/product_sku').read().strip()
|
||||
if model == 'none':
|
||||
raise Exception('No SKU')
|
||||
except Exception:
|
||||
model = open('/sys/devices/virtual/dmi/id/product_name').read()
|
||||
if vendor in ('Lenovo', 'IBM'):
|
||||
|
||||
@@ -114,7 +114,7 @@ def local_node_trust_setup():
|
||||
'IgnoreRhosts no'])
|
||||
if domain and not myname.endswith(domain):
|
||||
myprincipals.add('{0}.{1}'.format(myname, domain))
|
||||
if '.' in myname and myname.endswith(domain):
|
||||
if domain and '.' in myname and myname.endswith(domain):
|
||||
myprincipals.add(myname.split('.')[0])
|
||||
for pubkey in glob.glob('/etc/ssh/ssh_host_*_key.pub'):
|
||||
currpubkey = open(pubkey, 'rb').read()
|
||||
|
||||
@@ -209,14 +209,14 @@ node = {
|
||||
},
|
||||
'deployment.useinsecureprotocols': {
|
||||
'description': ('What phase(s) of boot are permitted to use insecure protocols '
|
||||
'(TFTP and HTTP without TLS. By default, HTTPS is allowed. However '
|
||||
'(TFTP and HTTP without TLS. By default, only HTTPS is used. However '
|
||||
'this is not compatible with most firmware in most scenarios. Using '
|
||||
'"firmware" as the setting will still use HTTPS after the initial download, '
|
||||
'though be aware that a successful compromise during the firmware phase '
|
||||
'though be aware that a successful attack during the firmware phase '
|
||||
'will negate future TLS protections. The value "always" will result in '
|
||||
'tftp/http being used for entire deployment. Note that ONIE does not '
|
||||
'support secure protocols, and in that case this setting must be "always" '
|
||||
'or "firmware"'),
|
||||
'tftp/http being used for most of the deployment. The value "never" will '
|
||||
'allow HTTPS only. Note that Ubuntu will still use HTTP without TLS for '
|
||||
'a phase of the installation process.'),
|
||||
'validlist': ('always', 'firmware', 'never'),
|
||||
},
|
||||
'discovery.passwordrules': {
|
||||
|
||||
@@ -81,6 +81,7 @@ import confluent.noderange as noderange
|
||||
import confluent.util as util
|
||||
import eventlet
|
||||
import traceback
|
||||
import socket as nsocket
|
||||
webclient = eventlet.import_patched('pyghmi.util.webclient')
|
||||
|
||||
|
||||
@@ -206,13 +207,16 @@ def uuid_is_valid(uuid):
|
||||
'00112233-4455-6677-8899-aabbccddeeff',
|
||||
'20202020-2020-2020-2020-202020202020')
|
||||
|
||||
def _printable_ip(sa):
|
||||
return nsocket.getnameinfo(
|
||||
sa, nsocket.NI_NUMERICHOST|nsocket.NI_NUMERICSERV)[0]
|
||||
|
||||
def send_discovery_datum(info):
|
||||
addresses = info.get('addresses', [])
|
||||
if info['handler'] == pxeh:
|
||||
enrich_pxe_info(info)
|
||||
yield msg.KeyValueData({'nodename': info.get('nodename', '')})
|
||||
yield msg.KeyValueData({'ipaddrs': [x[0] for x in addresses]})
|
||||
yield msg.KeyValueData({'ipaddrs': [_printable_ip(x) for x in addresses]})
|
||||
sn = info.get('serialnumber', '')
|
||||
mn = info.get('modelnumber', '')
|
||||
uuid = info.get('uuid', '')
|
||||
|
||||
@@ -14,13 +14,14 @@
|
||||
|
||||
import errno
|
||||
import eventlet
|
||||
import socket
|
||||
webclient = eventlet.import_patched('pyghmi.util.webclient')
|
||||
|
||||
class NodeHandler(object):
|
||||
https_supported = True
|
||||
is_enclosure = False
|
||||
devname = ''
|
||||
maxmacs = 2 # reasonable default, allowing for common scenario of
|
||||
maxmacs = 3 # reasonable default, allowing for common scenario of
|
||||
# shared nic in theory, but blocking enclosure managers
|
||||
# and uplink ports
|
||||
|
||||
@@ -38,7 +39,8 @@ class NodeHandler(object):
|
||||
else:
|
||||
if info.get('addresses', False):
|
||||
targsa = info['addresses'][0]
|
||||
self.ipaddr = targsa[0]
|
||||
self.ipaddr = socket.getnameinfo(
|
||||
targsa, socket.NI_NUMERICHOST|socket.NI_NUMERICSERV)[0]
|
||||
|
||||
@classmethod
|
||||
def adequate(cls, info):
|
||||
@@ -120,4 +122,4 @@ class NodeHandler(object):
|
||||
except Exception:
|
||||
self._certfailreason = 2
|
||||
return None
|
||||
return self._fp
|
||||
return self._fp
|
||||
|
||||
@@ -441,7 +441,7 @@ def check_reply(node, info, packet, sock, cfg, reqview):
|
||||
return
|
||||
rqtype = packet[53][0]
|
||||
insecuremode = cfd.get(node, {}).get('deployment.useinsecureprotocols',
|
||||
'never')
|
||||
{}).get('value', 'never')
|
||||
if not insecuremode:
|
||||
insecuremode = 'never'
|
||||
if insecuremode == 'never' and not httpboot:
|
||||
|
||||
Reference in New Issue
Block a user