Index: /package_tags/sipb-xen-console/8.0/debian/changelog
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/changelog	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/changelog	(revision 1063)
@@ -0,0 +1,151 @@
+sipb-xen-console (8.0) unstable; urgency=low
+
+  * Update config files to work with Hardy
+
+ -- Evan Broder <broder@mit.edu>  Sun, 05 Oct 2008 04:45:21 -0400
+
+sipb-xen-console (7.8) unstable; urgency=low
+
+  * generate config files using mako
+
+ -- Yang Zhang <y_z@mit.edu>  Thu, 14 Aug 2008 15:10:50 -0400
+
+sipb-xen-console (7.7) unstable; urgency=low
+
+  * sipb_xen_database -> invirt.database
+  * use invirt config in sipb-xen-consolefs
+  * added decomposition of DB URI
+  * generate nss-pgsql.conf and issue.net.no_tkt from debian init script
+
+ -- Yang Zhang <y_z@mit.edu>  Sun,  3 Aug 2008 01:13:37 -0400
+
+sipb-xen-console (7.6) unstable; urgency=low
+
+  * Use invirt-getconf to generate config.
+
+ -- Greg Price <price@mit.edu>  Wed, 30 Jul 2008 22:28:33 -0400
+
+sipb-xen-console (7.5) unstable; urgency=low
+
+  * Generate config at start/reload from /etc/invirt/*.
+
+ -- Greg Price <price@mit.edu>  Mon, 21 Jul 2008 18:29:43 -0400
+
+sipb-xen-console (7.4) unstable; urgency=low
+
+  * pull in sipb-xen-base
+
+ -- Greg Price <price@mit.edu>  Mon, 21 Jul 2008 17:41:01 -0400
+
+sipb-xen-console (7.3) unstable; urgency=low
+
+  * update for current config-package-dev
+
+ -- Greg Price <price@mit.edu>  Sun, 20 Jul 2008 15:41:50 -0400
+
+sipb-xen-console (7.3) unstable; urgency=low
+
+  * Move config details out to config package.
+
+ -- Greg Price <price@mit.edu>  Sun, 20 Jul 2008 01:01:26 -0400
+
+sipb-xen-console (7.2) unstable; urgency=low
+
+  * Multiplex consoles on multiple hosts.
+  
+ -- Greg Price <price@mit.edu>  Sun, 13 Jul 2008 08:52:18 -0400
+
+sipb-xen-console (7.1) unstable; urgency=low
+
+  * Remember to actually divert the conserver config
+
+ -- Evan Broder <broder@sipb-xen-dev.mit.edu>  Wed,  2 Apr 2008 01:48:05 -0400
+
+sipb-xen-console (7) unstable; urgency=low
+
+  * Use conserver instead of ssh to connect to black-mesa
+
+ -- Evan Broder <broder@sipb-xen-dev.mit.edu>  Wed,  2 Apr 2008 00:52:05 -0400
+
+sipb-xen-console (6.2) unstable; urgency=low
+
+  * /etc/modules is no longer managed by this package
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Tue,  1 Apr 2008 22:25:09 -0400
+
+sipb-xen-console (6.1) unstable; urgency=low
+
+  * Don't add the "d_" to the domain name on this side - do it on the
+    black-mesa side
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Tue, 01 Apr 2008 22:20:47 -0400
+
+sipb-xen-console (6) unstable; urgency=low
+
+  * modprobe fuse before attaching consolefs
+  * Revert code to block dropping privileges to user accounts
+  * Add configuration to accept Kerberos config for users and error on
+    non-root users if Kerberos authentication fails
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Tue, 01 Apr 2008 20:03:11 -0400
+
+sipb-xen-console (5.1) unstable; urgency=low
+
+  * Package should create /consolefs so that sipb-xen-consolefs has
+    somewhere to mount to
+
+ -- Evan Broder <broder@sipb-xen-dev.mit.edu>  Sun, 30 Mar 2008 18:20:02 -0400
+
+sipb-xen-console (5) unstable; urgency=low
+
+  * modprobe fuse at boot
+
+ -- Evan Broder <broder@sipb-xen-dev.mit.edu>  Sun, 30 Mar 2008 17:57:36 -0400
+
+sipb-xen-console (4.1) unstable; urgency=low
+
+  * It should not be trivial for us to access the serial console of
+    users' machines
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Sun, 30 Mar 2008 17:42:04 -0400
+
+sipb-xen-console (4) unstable; urgency=low
+
+  * Added comments to sipb-xen-consolefs
+  * Added support for symlinks in the realpath
+  * Changed sipb-xen-consolefs to use syslog instead of printf debugging
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Sun, 30 Mar 2008 14:17:59 -0400
+
+sipb-xen-console (3.2) unstable; urgency=low
+
+  * Fixing a bug in sipb-xen-consolefs ('@' is not re-added to realms
+    in the .k5login
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Sun, 30 Mar 2008 06:39:30 -0400
+
+sipb-xen-console (3.1) unstable; urgency=low
+
+  * Clean up the motd a bit
+  * Add dependency on sipb-xen-chrony-config to make sure the clock is
+    staying synced
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Sun, 30 Mar 2008 06:33:55 -0400
+
+sipb-xen-console (3) unstable; urgency=low
+
+  * Make the motd useful instead of turning it off
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Sun, 30 Mar 2008 06:14:23 -0400
+
+sipb-xen-console (2) unstable; urgency=low
+
+  * Actually functional release.
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Sun, 30 Mar 2008 05:07:43 -0400
+
+sipb-xen-console (1) unstable; urgency=low
+
+  * Initial release.
+
+ -- SIPB Xen Project <sipb-xen@mit.edu>  Sun, 30 Mar 2008 01:08:50 -0400
Index: /package_tags/sipb-xen-console/8.0/debian/compat
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/compat	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/compat	(revision 1063)
@@ -0,0 +1,1 @@
+5
Index: /package_tags/sipb-xen-console/8.0/debian/control
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/control	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/control	(revision 1063)
@@ -0,0 +1,15 @@
+Source: sipb-xen-console
+Section: servers
+Priority: extra
+Maintainer: SIPB Xen Project <sipb-xen@mit.edu>
+Build-Depends: cdbs (>= 0.4.23-1.1), debhelper (>= 5), config-package-dev (>= 4.5~), nscd, openssh-server, debathena-ssh-server-config, initscripts
+Standards-Version: 3.7.2
+
+Package: sipb-xen-console
+Architecture: all
+Provides: ${diverted-files}
+Conflicts: ${diverted-files}
+Depends: sipb-xen-base, ${shlibs:Depends}, ${misc:Depends}, conserver-client, daemon, debathena-kerberos-config, fuse-utils, libnss-pgsql1, nscd, openssh-server, python, python-fuse, sipb-xen-chrony-config, sipb-xen-database-common, remctl-server
+Description: SIPB Xen serial console server
+ This package  should be installed on sipb-xen-console
+ It makes sure that necessary tools are available.
Index: /package_tags/sipb-xen-console/8.0/debian/copyright
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/copyright	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/copyright	(revision 1063)
@@ -0,0 +1,3 @@
+This package was created for internal use of the SIPB Xen Project of
+the MIT Student Information Processing Board.  Ask sipb-xen@mit.edu if
+you have questions about redistribution.
Index: /package_tags/sipb-xen-console/8.0/debian/rules
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/rules	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/rules	(revision 1063)
@@ -0,0 +1,21 @@
+#!/usr/bin/make -f
+
+DEB_DIVERT_EXTENSION = .sipb-xen
+DEB_TRANSFORM_FILES_sipb-xen-console += \
+	/etc/init.d/bootmisc.sh.sipb-xen \
+	/etc/nsswitch.conf.sipb-xen \
+	/etc/nscd.conf.sipb-xen \
+	/etc/pam.d/sshd.sipb-xen \
+	/etc/ssh/sshd_config.debathena.sipb-xen
+
+ifneq ($(wildcard /usr/share/base-files/nsswitch.conf),)
+    DEB_CHECK_FILES_SOURCE_/etc/nsswitch.conf.sipb-xen = \
+        /usr/share/base-files/nsswitch.conf
+endif
+
+DEB_DIVERT_FILES_sipb-xen-console += \
+	/etc/conserver/conserver.cf.sipb-xen \
+	/etc/motd.sipb-xen
+
+include /usr/share/cdbs/1/rules/debhelper.mk
+include /usr/share/cdbs/1/rules/config-package.mk
Index: /package_tags/sipb-xen-console/8.0/debian/sipb-xen-console.init
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/sipb-xen-console.init	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/sipb-xen-console.init	(revision 1063)
@@ -0,0 +1,135 @@
+#!/bin/bash
+### BEGIN INIT INFO
+# Provides:          sipb-xen-console
+# Required-Start:    $local_fs $remote_fs
+# Required-Stop:     $local_fs $remote_fs
+# Default-Start:     2 3 4 5
+# Default-Stop:      0 1 6
+# Short-Description: sipb-xen Console Server homedir filesystem
+# Description:       
+### END INIT INFO
+
+# Author: SIPB Xen Project <sipb-xen@mit.edu>
+
+# Do NOT "set -e"
+
+# PATH should only include /usr/* if it runs after the mountnfs.sh script
+PATH=/sbin:/usr/sbin:/bin:/usr/bin
+DESC="The sipb-xen console server"
+NAME=sipb-xen-console
+DAEMON=/usr/bin/sipb-xen-consolefs
+DAEMON_ARGS="/consolefs"
+PIDFILE=/var/run/$NAME.pid
+SCRIPTNAME=/etc/init.d/$NAME
+
+# Exit if the package is not installed
+[ -x "$DAEMON" ] || exit 0
+
+# Read configuration variable file if it is present
+[ -r /etc/default/$NAME ] && . /etc/default/$NAME
+
+# Load the VERBOSE setting and other rcS variables
+. /lib/init/vars.sh
+
+# Define LSB log_* functions.
+# Depend on lsb-base (>= 3.0-6) to ensure that this file is present.
+. /lib/lsb/init-functions
+
+gen_config()
+{
+    for i in /etc/conserver/invirt-hosts.cf \
+             /etc/remctl/acl/invirt-console \
+             /etc/issue.net.no_tkt \
+             /etc/nss-pgsql.conf \
+             ; do
+        mako-render $i.mako > $i
+    done
+}
+
+#
+# Function that starts the daemon/service
+#
+do_start()
+{
+	# Return
+	#   0 if daemon has been started
+	#   1 if daemon was already running
+	#   2 if daemon could not be started
+	modprobe fuse
+	gen_config
+	daemon --running -n $NAME && return 1
+	daemon -r -O daemon.info -E daemon.err -n $NAME -U $DAEMON $DAEMON_ARGS || return 2
+}
+
+#
+# Function that stops the daemon/service
+#
+do_stop()
+{
+	# Return
+	#   0 if daemon has been stopped
+	#   1 if daemon was already stopped
+	#   2 if daemon could not be stopped
+	#   other if a failure occurred
+	daemon --stop -n $NAME
+	RETVAL="$?"
+	[ "$RETVAL" = 2 ] && return 2
+	# Many daemons don't delete their pidfiles when they exit.
+	rm -f $PIDFILE
+	umount "$DAEMON_ARGS"
+	return "$RETVAL"
+}
+
+do_reload()
+{
+	gen_config
+	/etc/init.d/conserver-server reload
+}
+
+case "$1" in
+  start)
+	[ "$VERBOSE" != no ] && log_daemon_msg "Starting $DESC" "$NAME"
+	do_start
+	case "$?" in
+		0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
+		2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
+	esac
+	;;
+  stop)
+	[ "$VERBOSE" != no ] && log_daemon_msg "Stopping $DESC" "$NAME"
+	do_stop
+	case "$?" in
+		0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
+		2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
+	esac
+	;;
+  reload|force-reload)
+	log_daemon_msg "Reloading $DESC" "$NAME"
+	do_reload
+	log_end_msg $?
+	;;
+  restart)
+	log_daemon_msg "Restarting $DESC" "$NAME"
+	do_stop
+	case "$?" in
+	  0|1)
+		do_start
+		case "$?" in
+			0) log_end_msg 0 ;;
+			1) log_end_msg 1 ;; # Old process is still running
+			*) log_end_msg 1 ;; # Failed to start
+		esac
+		;;
+	  *)
+	  	# Failed to stop
+		log_end_msg 1
+		;;
+	esac
+	;;
+  *)
+	echo "Usage: $SCRIPTNAME {start|stop|restart|reload|force-reload}" >&2
+	exit 3
+	;;
+esac
+
+:
Index: /package_tags/sipb-xen-console/8.0/debian/sipb-xen-console.install
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/sipb-xen-console.install	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/sipb-xen-console.install	(revision 1063)
@@ -0,0 +1,1 @@
+files/* .
Index: /package_tags/sipb-xen-console/8.0/debian/transform_bootmisc.sh.sipb-xen
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/transform_bootmisc.sh.sipb-xen	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/transform_bootmisc.sh.sipb-xen	(revision 1063)
@@ -0,0 +1,14 @@
+#!/bin/bash
+patch -p0 -o /dev/fd/4 3<&0 4>&1 1>/dev/null <<EOF
+
+# Yes, I there's no context. But the lines being replaced are less
+# likely to change than the lines around them
+
+--- Ignored
++++ /dev/fd/3
+@@ -42,3 +42,2 @@
+-	# Update motd
+-	uname -snrvm > /var/run/motd
+-	[ -f /etc/motd.tail ] && cat /etc/motd.tail >> /var/run/motd
++	# Do not update motd
++	cp /etc/motd /var/run/motd
Index: /package_tags/sipb-xen-console/8.0/debian/transform_nscd.conf.sipb-xen
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/transform_nscd.conf.sipb-xen	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/transform_nscd.conf.sipb-xen	(revision 1063)
@@ -0,0 +1,6 @@
+#!/usr/bin/perl -0p
+s/^(\s*negative-time-to-live\s*passwd\s*).*$/\13/m or die;
+s/^(\s*negative-time-to-live\s*group\s*).*$/\13/m or die;
+s/^(\s*persistent\s*passwd\s*).*$/\1no/m or die;
+s/^(\s*persistent\s*group\s*).*$/\1no/m or die;
+
Index: /package_tags/sipb-xen-console/8.0/debian/transform_nsswitch.conf.sipb-xen
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/transform_nsswitch.conf.sipb-xen	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/transform_nsswitch.conf.sipb-xen	(revision 1063)
@@ -0,0 +1,3 @@
+#!/usr/bin/perl -0p
+s/^(passwd: .*)$/$1 pgsql/m or die;
+s/^(group: .*)$/$1 pgsql/m or die;
Index: /package_tags/sipb-xen-console/8.0/debian/transform_sshd.sipb-xen
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/transform_sshd.sipb-xen	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/transform_sshd.sipb-xen	(revision 1063)
@@ -0,0 +1,11 @@
+#!/bin/sh
+echo "# If they're not root, but their user exists (success),"
+echo 'auth    [success=ignore ignore=ignore default=1 module_unknown=die]   pam_succeed_if.so uid > 0'
+echo "# print the \"You don\'t have tickets\" error:"
+echo 'auth    [success=die ignore=reset default=die module_unknown=die]     pam_echo.so file=/etc/issue.net.no_tkt'
+echo "# If !(they are root),"
+echo 'auth    [success=1 ignore=ignore default=ignore module_unknown=die]   pam_succeed_if.so uid eq 0'
+echo "# print the \"your account doesn't exist\" error:"
+echo 'auth    [success=die ignore=reset default=die module_unknown=die]     pam_echo.so file=/etc/issue.net.no_user'
+echo
+exec cat
Index: /package_tags/sipb-xen-console/8.0/debian/transform_sshd_config.debathena.sipb-xen
===================================================================
--- /package_tags/sipb-xen-console/8.0/debian/transform_sshd_config.debathena.sipb-xen	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/debian/transform_sshd_config.debathena.sipb-xen	(revision 1063)
@@ -0,0 +1,2 @@
+#!/usr/bin/perl -0p
+s/^#?PrintLastLog .*$/PrintLastLog no/m or die;
Index: /package_tags/sipb-xen-console/8.0/files/etc/conserver/conserver.cf.sipb-xen
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/etc/conserver/conserver.cf.sipb-xen	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/etc/conserver/conserver.cf.sipb-xen	(revision 1063)
@@ -0,0 +1,13 @@
+# default config for console
+config * {
+	sslrequired yes;
+}
+default * {
+        type exec;
+}
+access * {
+        trusted 127.0.0.1;
+        limited *;
+}
+
+#include /etc/conserver/invirt-hosts.cf
Index: /package_tags/sipb-xen-console/8.0/files/etc/conserver/console.cf
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/etc/conserver/console.cf	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/etc/conserver/console.cf	(revision 1063)
@@ -0,0 +1,5 @@
+config * {
+  master localhost;
+  port   3109;
+  sslenabled yes;
+}
Index: /package_tags/sipb-xen-console/8.0/files/etc/conserver/invirt-hosts.cf.mako
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/etc/conserver/invirt-hosts.cf.mako	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/etc/conserver/invirt-hosts.cf.mako	(revision 1063)
@@ -0,0 +1,4 @@
+<% from invirt.config import structs as cfg %>\
+% for h in cfg.hosts:
+#include /etc/conserver/conf.d/${h.hostname}
+% endfor
Index: /package_tags/sipb-xen-console/8.0/files/etc/issue.net.no_tkt.mako
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/etc/issue.net.no_tkt.mako	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/etc/issue.net.no_tkt.mako	(revision 1063)
@@ -0,0 +1,4 @@
+<% from invirt.config import structs as cfg %>\
+You must login to the ${cfg.console.hostname} console server using
+Kerberos tickets, but your ssh client did not pass a valid ticket to the
+console server.
Index: /package_tags/sipb-xen-console/8.0/files/etc/issue.net.no_user
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/etc/issue.net.no_user	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/etc/issue.net.no_user	(revision 1063)
@@ -0,0 +1,2 @@
+The VM you are attempting to access does not appear to exist.
+
Index: /package_tags/sipb-xen-console/8.0/files/etc/motd.sipb-xen
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/etc/motd.sipb-xen	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/etc/motd.sipb-xen	(revision 1063)
@@ -0,0 +1,3 @@
+
+Type Ctrl-e, then c, then . to escape from the console
+
Index: /package_tags/sipb-xen-console/8.0/files/etc/nss-pgsql.conf.mako
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/etc/nss-pgsql.conf.mako	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/etc/nss-pgsql.conf.mako	(revision 1063)
@@ -0,0 +1,16 @@
+<% from invirt.config import structs as cfg %>
+host        = ${cfg.db.host}
+port        = ${cfg.db.port}
+database    = ${cfg.db.dbname}
+login       = ${cfg.db.user}
+
+querypasswd = SELECT name, NULL, machine_id + 1000 as uid, machine_id + 1000 as gid, '', '/consolefs/'|| name, '/usr/bin/sipb-xen-consolesh' FROM machines
+querygroup = SELECT name, NULL, machine_id + 1000 as gid FROM machines
+querymembers = SELECT name FROM machines WHERE 1000 + machine_id = %d
+queryids = SELECT 1000 + machine_id AS gid FROM machines LIMIT 0
+
+passwd_name = name
+passwd_uid = 1000 + machine_id
+
+group_name = name
+group_gid = 1000 + machine_id
Index: /package_tags/sipb-xen-console/8.0/files/etc/remctl/acl/invirt-console.mako
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/etc/remctl/acl/invirt-console.mako	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/etc/remctl/acl/invirt-console.mako	(revision 1063)
@@ -0,0 +1,4 @@
+<% from invirt.config import structs as cfg %>\
+% for h in cfg.hosts:
+host/${h.hostname}@${cfg.authn[0].realm}
+% endfor
Index: /package_tags/sipb-xen-console/8.0/files/etc/remctl/conf.d/invirt-console
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/etc/remctl/conf.d/invirt-console	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/etc/remctl/conf.d/invirt-console	(revision 1063)
@@ -0,0 +1,1 @@
+console update /usr/sbin/invirt-console-update /etc/remctl/acl/invirt-console
Index: /package_tags/sipb-xen-console/8.0/files/usr/bin/sipb-xen-consolefs
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/usr/bin/sipb-xen-consolefs	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/usr/bin/sipb-xen-consolefs	(revision 1063)
@@ -0,0 +1,249 @@
+#!/usr/bin/python
+
+import fuse
+from fuse import Fuse
+
+from time import time
+
+import stat	# for file properties
+import os	  # for filesystem modes (O_RDONLY, etc)
+import errno   # for error number codes (ENOENT, etc)
+			   # - note: these must be returned as negatives
+
+from syslog import *
+
+from invirt.config import structs as config
+from invirt import database
+
+fuse.fuse_python_api = (0, 2)
+
+realpath = "/home/machines/"
+
+def getDepth(path):
+	"""
+	Return the depth of a given path, zero-based from root ('/')
+	"""
+	if path == '/':
+		return 0
+	else:
+		return path.count('/')
+
+def getParts(path):
+	"""
+	Return the slash-separated parts of a given path as a list
+	"""
+	if path == '/':
+		return ['/']
+	else:
+		# [1:] because otherwise you get an empty list element from the
+		# initial '/'
+		return path[1:].split('/')
+
+class MyStat:
+	def __init__(self):
+		self.st_mode = 0
+		self.st_ino = 0
+		self.st_dev = 0
+		self.st_nlink = 0
+		self.st_uid = 0
+		self.st_gid = 0
+		self.st_size = 0
+		self.st_atime = 0
+		self.st_mtime = 0
+		self.st_ctime = 0
+	
+	def toTuple(self):
+		return (self.st_mode, self.st_ino, self.st_dev, self.st_nlink, self.st_uid, self.st_gid, self.st_size, self.st_atime, self.st_mtime, self.st_ctime)
+
+class ConsoleFS(Fuse):
+	"""
+	ConsoleFS creates a series of subdirectories each mirroring the same real
+	directory, except for a single file - the .k5login - which is dynamically
+	generated for each subdirectory
+	
+	This filesystem only implements the getattr, getdir, read, and readlink
+	calls, beacuse this is a read-only filesystem
+	"""
+	
+	def __init__(self, *args, **kw):
+		"""Initialize the filesystem and set it to allow_other access besides
+		the user who mounts the filesystem (i.e. root)
+		"""
+		Fuse.__init__(self, *args, **kw)
+		self.lasttime = time()
+		self.allow_other = 1
+		
+		openlog('sipb-xen-consolefs ', LOG_PID, LOG_DAEMON)
+		
+		syslog(LOG_DEBUG, 'Init complete.')
+	
+	def mirrorPath(self, path):
+		"""Translate a virtual path to its real path counterpart"""
+		return realpath + "/".join(getParts(path)[1:])
+	
+	def getMachines(self):
+		"""Get the list of VMs in the database, clearing the cache if it's 
+		older than 15 seconds"""
+		if time() - self.lasttime > 15:
+			self.lasttime = time()
+			database.clear_cache()
+		return [machine.name for machine in database.Machine.select()]
+	
+	def getUid(self, machine_name):
+		"""Calculate the UID of a machine-account, which is just machine_id+1000
+		"""
+		return database.Machine.get_by(name=machine_name).machine_id + 1000
+	
+	def getK5login(self, machine_name):
+		"""Build the ACL for a machine and turn it into a .k5login file
+		"""
+		machine = database.Machine.get_by(name=machine_name)
+		users = [acl.user for acl in machine.acl]
+		return "\n".join(map(self.userToPrinc, users) + [''])
+	
+	def userToPrinc(self, user):
+		"""Convert Kerberos v4-style names to v5-style and append a default
+		realm if none is specified
+		"""
+		if '@' in user:
+			(princ, realm) = user.split('@')
+		else:
+			princ = user
+			realm = config.authn[0].realm
+		
+		return princ.replace('.', '/') + '@' + realm
+	
+	def getattr(self, path):
+		"""
+		- st_mode (protection bits)
+		- st_ino (inode number)
+		- st_dev (device)
+		- st_nlink (number of hard links)
+		- st_uid (user ID of owner)
+		- st_gid (group ID of owner)
+		- st_size (size of file, in bytes)
+		- st_atime (time of most recent access)
+		- st_mtime (time of most recent content modification)
+		- st_ctime (platform dependent; time of most recent metadata change on Unix,
+					or the time of creation on Windows).
+		"""
+		
+		syslog(LOG_DEBUG, "*** getattr: " + path)
+		
+		depth = getDepth(path)
+		parts = getParts(path)
+		
+		st = MyStat()
+		# / is a directory
+		if path == '/':
+			st.st_mode = stat.S_IFDIR | 0755
+			st.st_nlink = 2
+		# /foo is a directory if foo is a machine - otherwise it doesn't exist
+		elif depth == 1:
+			if parts[-1] in self.getMachines():
+				st.st_mode = stat.S_IFDIR | 0755
+				st.st_nlink = 2
+				# Homedirs should be owned by the user whose homedir it is
+				st.st_uid = st.st_gid = self.getUid(parts[0])
+			else:
+				return -errno.ENOENT
+		# Catch the .k5login file, because it's a special case
+		elif depth == 2 and parts[-1] == '.k5login':
+			st.st_mode = stat.S_IFREG | 0444
+			st.st_nlink = 1
+			st.st_size = len(self.getK5login(parts[0]))
+			# The .k5login file should be owned by the user whose homedir it is
+			st.st_uid = st.st_gid = self.getUid(parts[0])
+		# For anything else, we get the mirror path and call out to the OS
+		else:
+			stats = list(os.lstat(self.mirrorPath(path)))
+			# Shadow the UID and GID from the original homedir
+			stats[4:6] = [self.getUid(parts[0])] * 2
+			return tuple(stats)
+		return st.toTuple()
+	
+	# This call isn't actually used in the version of Fuse on console, but we
+	# wanted to leave it implemented to ease the transition in the future
+	def readdir(self, path, offset):
+		"""Return a generator with the listing for a directory
+		"""
+		syslog(LOG_DEBUG, '*** readdir %s %s' % (path, offset))
+		for (value, zero) in self.getdir(path):
+			yield fuse.Direntry(value)
+	
+	def getdir(self, path):
+		"""Return a list of tuples of the form (item, 0) with the contents of
+		the directory path
+		
+		Fuse doesn't add '.' or '..' on its own, so we have to
+		"""
+		syslog(LOG_DEBUG, '*** getdir %s' % path)
+		
+		# '/' contains a directory for each machine
+		if path == '/':
+			contents = self.getMachines()
+		# The directory for each machine contains the same files as the realpath
+		# but also the .k5login
+		#
+		# The list is converted to a set so that we can handle the case where 
+		# there is already a .k5login in the realpath gracefully
+		elif getDepth(path) == 1:
+			contents = set(os.listdir(self.mirrorPath(path)) + ['.k5login'])
+		# If it's not the root of the homedir, just pass the call onto the OS
+		# for realpath
+		else:
+			contents = os.listdir(self.mirrorPath(path))
+		# Format the list the way that Fuse wants it - and don't forget to add
+		# '.' and '..'
+		return [(i, 0) for i in (list(contents) + ['.', '..'])]
+	
+	def read(self, path, length, offset):
+		"""Read length bytes starting at offset of path. In most cases, this
+		just gets passed on to the OS
+		"""
+		syslog(LOG_DEBUG, '*** read %s %s %s' % (path, length, offset))
+		
+		parts = getParts(path)
+		
+		# If the depth is less than 2, then either it's a directory or the file
+		# doesn't exist
+		# (realistically this doesn't appear to ever happen)
+		if getDepth(path) < 2:
+			return -errno.ENOENT
+		# If we're asking for a real .k5login file, then create it and return
+		# the snippet requested
+		elif parts[1:] == ['.k5login']:
+			if parts[0] not in self.getMachines():
+				return -errno.ENOENT
+			else:
+				return self.getK5login(parts[0])[offset:length + offset]
+		# Otherwise, pass the call onto the OS
+		# (note that the file will get closed when this call returns and the
+		# file descriptor goes out of scope)
+		else:
+			fname = self.mirrorPath(path)
+			if not os.path.isfile(fname):
+				return -errno.ENOENT
+			else:
+				f = open(fname)
+				f.seek(offset)
+				return f.read(length)
+	
+	def readlink(self, path):
+		syslog(LOG_DEBUG, '*** readlink %s' % path)
+		
+		# There aren't any symlinks here
+		if getDepth(path) < 2:
+			return -errno.ENOENT
+		# But there might be here
+		else:
+			return os.readlink(self.mirrorPath(path))
+
+if __name__ == '__main__':
+	database.connect()
+	usage="""
+ConsoleFS [mount_path]
+"""
+	server = ConsoleFS()
+	server.flags = 0
+	server.main()
Index: /package_tags/sipb-xen-console/8.0/files/usr/bin/sipb-xen-consolesh
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/usr/bin/sipb-xen-consolesh	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/usr/bin/sipb-xen-consolesh	(revision 1063)
@@ -0,0 +1,2 @@
+#!/bin/bash
+exec /usr/bin/console "$USER"
Index: /package_tags/sipb-xen-console/8.0/files/usr/sbin/invirt-console-update
===================================================================
--- /package_tags/sipb-xen-console/8.0/files/usr/sbin/invirt-console-update	(revision 1063)
+++ /package_tags/sipb-xen-console/8.0/files/usr/sbin/invirt-console-update	(revision 1063)
@@ -0,0 +1,18 @@
+#!/usr/bin/python
+import sys
+import os
+import subprocess
+
+def main(args):
+  contents = args[2]
+  hostname = os.environ['REMOTE_HOST'].lower()
+  f = file('/etc/conserver/conf.d/'+hostname, 'w')
+  f.write(contents)
+  f.close()
+  p = subprocess.Popen(['/etc/init.d/conserver-server', 'reload'],
+                       stdout=subprocess.PIPE)
+  p.wait()
+  return 0
+
+if __name__ == '__main__':
+  sys.exit(main(sys.argv))
