Skip to content
This repository


harlowja edited this page · 30 revisions


Method information



Uri: http://$HOST:$PORT/$PATH/

Notes: Performed using euca-run-instances using euca2ools_2.0.0~bzr464-0ubuntu2 on Ubuntu 11.10



  1. MaxCount can be >= MinCount (is there any validation on this?)
  2. ImageId must be an existent and accessible image identifier
  3. InstanceType must be an existent and accessible flavor

Exact version requested: 2009-11-30

Restricted to: projectmanager, sysadmin





Expected response

An XML response (with status code 200) conforming to the previous XSD would be expected.

Actual response

<?xml version="1.0" ?>
<RunInstancesResponse xmlns="">
            <availabilityZone>unknown zone</availabilityZone>


An error will be sent back in the following XML format (with a 400 status code):

<?xml version="1.0"?>


  1. EC2APIError
  2. ImageNotFound
  3. InstanceLimitExceeded
  4. InstanceTypeDiskTooSmall
  5. InstanceTypeMemoryTooSmall
  6. InstanceTypeNotFoundByName
  7. InvalidInstanceIDMalformed
  8. InvalidParameterValue
  9. InvalidRequest
  10. NotAuthorized
  11. QuotaError
  12. SecurityGroupNotFound
  13. SecurityGroupNotFoundForProject
  14. Unauthorized (huh, duplicate of NotAuthorized?)
  15. UnknownError
  16. (Others??)


  1. Does not comply to defined schema (ordering mainly)

$ ../data/xsds/2009-11-30.ec2.wsdl.xsd ../req.xml

org.xml.sax.SAXParseException: cvc-complex-type.2.4.a: Invalid content was found starting with element 'ownerId'. One of '{"":reservationId}' is expected.
org.xml.sax.SAXParseException: cvc-complex-type.2.4.a: Invalid content was found starting with element 'placement'. One of '{"":instanceId}' is expected.
  1. Version support is weak/non-existent; code copies input version parameter and echos it back
  2. No validation on input of the given version
  3. No validation of the output
    • Does not ensure it conforms to a given version
    • No concept of separate renderers for all supported versions
  4. launchTime is not compliant with the expected xs:dateTime format
  5. Request parameters not implemented
    • Monitoring.Enabled
    • AddressingType
    • SubnetId
    • DisableApiTermination
    • InstanceInitiatedShutdownBehavior
  6. Non-compliant request parameters
    • KeyName (?)
    • UserData (post data?)
  7. Weak to non-existent list of error messages which can be returned
  8. Mapping to EC2 error codes is incorrect
  9. Little parameter validation (ie all args are converted into python uncamelcased objects/lists)
    • This could lead to exploits/DOS/python running out of memory...
  10. Error XML response creation does not do XML escaping, see LP bug #978439
Something went wrong with that request. Please try again.